VYPR

Opencart

by Opencart

Source repositories

CVEs (50)

  • CVE-2021-47923CriMay 10, 2026
    risk 0.64cvss 9.8epss 0.00

    OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting arbitrary values into the OCSESSID cookie. Attackers can set malicious OCSESSID cookie values that the server accepts and maintains, enabling session takeover…

  • CVE-2023-40834CriSep 12, 2023
    risk 0.64cvss 9.8epss 0.01

    OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated attackers to gain access to the application via a brute force attack to the password parameter.

  • CVE-2022-41403CriOct 12, 2022
    risk 0.64cvss 9.8epss 0.01

    OpenCart 3.x Newsletter Custom Popup was discovered to contain a SQL injection vulnerability via the email parameter at index.php?route=extension/module/so_newletter_custom_popup/newsletter.

  • CVE-2022-34972CriJul 5, 2022
    risk 0.64cvss 9.8epss 0.01

    So Filter Shop v3.x was discovered to contain multiple blind SQL injection vulnerabilities via the att_value_id , manu_value_id , opt_value_id , and subcate_value_id parameters at /index.php?route=extension/module/so_filter_shop_by/filter_data.

  • CVE-2026-18412CriAug 10, 2026
    risk 0.59cvss 9.1epss 0.00

    OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 extension installer extracts these zip files, but does not validate that the extracted paths stay inside the intended extraction directory. An attacker can craft a…

  • CVE-2023-47444HigNov 15, 2023
    risk 0.57cvss 8.8epss 0.02

    An issue discovered in OpenCart 4.0.0.0 to 4.0.2.3 allows authenticated backend users having common/security write privilege can write arbitrary untrusted data inside config.php and admin/config.php, resulting in remote code execution on the underlying server.

  • CVE-2018-13067HigJul 2, 2018
    risk 0.57cvss 8.8epss 0.01

    /upload/catalog/controller/account/password.php in OpenCart through 3.0.2.0 has CSRF via the index.php?route=account/password URI to change a user's password.

  • CVE-2014-3990CriMar 20, 2018
    risk 0.57cvss 9.8epss 0.07

    The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forgery (SSRF) attacks or possibly conduct XML External Entity (XXE) attacks and execute arbitrary code via a crafted serialized PHP…

  • CVE-2017-20282HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component jCart for OpenCart 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the product_id parameter. Attackers can send GET requests to index.php with the…

  • CVE-2024-58341HigMar 25, 2026
    risk 0.53cvss 8.2epss 0.00

    OpenCart Core 4.0.2.3 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'search' parameter. Attackers can send GET requests to the product search endpoint with malicious 'search' values…

  • CVE-2018-11231HigMay 23, 2018
    risk 0.53cvss 8.1epss 0.09

    In the Divido plugin for OpenCart, there is SQL injection. Attackers can use SQL injection to get some confidential information.

  • CVE-2018-11494HigMay 26, 2018
    risk 0.52cvss 8.0epss 0.02

    The "program extension upload" feature in OpenCart through 3.0.2.0 has a six-step process (upload, install, unzip, move, xml, remove) that allows attackers to execute arbitrary code if the remove step is skipped, because the attacker can discover a secret temporary directory…

  • CVE-2024-21518HigJun 22, 2024
    risk 0.48cvss 7.2epss 0.14

    This affects versions of the package opencart/opencart from 4.0.0.0. A Zip Slip issue was identified via the marketplace installer due to improper sanitization of the target path, allowing files within a malicious archive to traverse the filesystem and be extracted to arbitrary…

  • CVE-2020-20491HigJun 20, 2023
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability in OpenCart v.2.2.00 thru 3.0.3.2 allows a remote attacker to execute arbitrary code via the Fba plugin function in upload/admin/index.php.

  • CVE-2023-2315HigSep 27, 2023
    risk 0.46cvss 8.1epss 0.01

    Path Traversal in OpenCart versions 4.0.0.0 to 4.0.2.2 allows an authenticated user with access/modify privilege on the Log component to empty out arbitrary files on the server

  • CVE-2024-21519MedJun 22, 2024
    risk 0.43cvss 6.6epss 0.01

    This affects versions of the package opencart/opencart from 4.0.0.0. An Arbitrary File Creation issue was identified via the database restoration functionality. By injecting PHP code into the database, an attacker with admin privileges can create a backup file with an arbitrary…

  • CVE-2024-21514HigJun 22, 2024
    risk 0.43cvss 7.4epss 0.19

    This affects versions of the package opencart/opencart from 0.0.0. An SQL Injection issue was identified in the Divido payment extension for OpenCart, which is included by default in version 3.0.3.9. As an anonymous unauthenticated user, if the Divido payment module is installed…

  • CVE-2025-45893MedJul 25, 2025
    risk 0.40cvss 6.1epss 0.00

    OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via SVG file uploads used in blog posts. The vulnerability arises because SVG files uploaded through the media manager are not properly sanitized. Attackers can craft a malicious SVG file…

  • CVE-2025-45892MedJul 25, 2025
    risk 0.40cvss 6.1epss 0.00

    OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via the blog editor. The vulnerability arises because input in the blog's editor is not properly sanitized or escaped before being rendered. This allows attackers to inject malicious JavaScript…

  • CVE-2025-1746MedFeb 28, 2025
    risk 0.40cvss 6.1epss 0.00

    Cross-Site Scripting vulnerability in OpenCart versions prior to 4.1.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the search in the /product/search endpoint. This vulnerability could be…

Page 1 of 3