Medium severity6.1NVD Advisory· Published Jul 25, 2025· Updated Jun 17, 2026
CVE-2025-45893
CVE-2025-45893
Description
OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via SVG file uploads used in blog posts. The vulnerability arises because SVG files uploaded through the media manager are not properly sanitized. Attackers can craft a malicious SVG file containing embedded JavaScript
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4Patches
Vulnerability mechanics
References
2- packetstorm.news/files/id/202886nvdThird Party Advisory
- www.opencart.comnvdProduct
News mentions
0No linked articles in our index yet.