Opencart / Opencart
40 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-84438 | OpenCart Autocomplete Workflow edit.php cross site scripting | MEDIUM | 5.1 | Sep 2, 2026 |
| CVE-2026-84437 | OpenCart Autocomplete Workflow address.php cross site scripting | MEDIUM | 5.1 | Sep 2, 2026 |
| CVE-2026-18412 | The OpenCart v4.2.0.0 extension installer contains a directory traversal vulnerability | CRITICAL | 9.1 | Aug 10, 2026 |
| CVE-2021-47953 | OpenCart 3.0.3.7 Cross-Site Request Forgery via account/password | MEDIUM | 5.3 | May 10, 2026 |
| CVE-2021-47946 | OpenCart 3.0.3.6 Account Takeover via Cross Site Request Forgery | MEDIUM | 6.9 | May 10, 2026 |
| CVE-2021-47923 | OpenCart 3.0.3.8 Session Fixation via OCSESSID Cookie | CRITICAL | 9.3 | May 10, 2026 |
| CVE-2026-5331 | OpenCart Extension Installer installer.php path traversal | MEDIUM | 5.1 | Apr 2, 2026 |
| CVE-2024-58341 | OpenCart Core 4.0.2.3 SQL Injection via search Parameter | HIGH | 8.8 | Mar 25, 2026 |
| CVE-2026-3714 | OpenCart Incomplete Fix CVE-2024-36694 template.php save special elements used in a template engine | MEDIUM | 5.1 | Mar 8, 2026 |
| CVE-2025-15116 | OpenCart Single-Use Coupon race condition | MEDIUM | 6.3 | Dec 28, 2025 |
| CVE-2025-45893 | OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via SVG file uploads used in blog posts. The vulnerability arises because… | MEDIUM | 6.1 | Jul 25, 2025 |
| CVE-2025-45892 | OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via the blog editor. The vulnerability arises because input in the blog's… | MEDIUM | 6.1 | Jul 25, 2025 |
| CVE-2025-1749 | HTML injection vulnerability in OpenCart | MEDIUM | 4.7 | Feb 28, 2025 |
| CVE-2025-1748 | HTML injection vulnerability in OpenCart | MEDIUM | 4.7 | Feb 28, 2025 |
| CVE-2025-1747 | HTML injection vulnerability in OpenCart | MEDIUM | 4.7 | Feb 28, 2025 |
| CVE-2025-1746 | Cross-Site Scripting vulnerability in OpenCart | MEDIUM | 6.1 | Feb 28, 2025 |
| CVE-2024-36694 | OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function. | MEDIUM | 5.5 | Dec 18, 2024 |
| CVE-2024-21516 | This affects versions of the package opencart/opencart from 4.0.0.0 and before 4.1.0.0. A reflected XSS issue was identified in the directory parameter of admi… | LOW | 2.1 | Jun 22, 2024 |
| CVE-2024-21519 | This affects versions of the package opencart/opencart from 4.0.0.0. An Arbitrary File Creation issue was identified via the database restoration functionality… | HIGH | 7.1 | Jun 22, 2024 |
| CVE-2024-21514 | This affects versions of the package opencart/opencart from 0.0.0. An SQL Injection issue was identified in the Divido payment extension for OpenCart, which is… | HIGH | 8.1 | Jun 22, 2024 |
| CVE-2024-21518 | This affects versions of the package opencart/opencart from 4.0.0.0. A Zip Slip issue was identified via the marketplace installer due to improper sanitization… | HIGH | 8.4 | Jun 22, 2024 |
| CVE-2024-21517 | This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the redirect parameter of customer account/login r… | LOW | 2.1 | Jun 22, 2024 |
| CVE-2024-21515 | This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the filename parameter of the admin tool/log route… | LOW | 2.1 | Jun 22, 2024 |
| CVE-2023-47444 | An issue discovered in OpenCart 4.0.0.0 to 4.0.2.3 allows authenticated backend users having common/security write privilege can write arbitrary untrusted data… | HIGH | 8.8 | Nov 15, 2023 |
| CVE-2023-2315 | Path Traversal in OpenCart versions 4.0.0.0 to 4.0.2.2 | HIGH | 8.8 | Sep 26, 2023 |
Showing 1 to 25 of 40 CVEs