VYPR

Opencart

by Opencart

Source repositories

CVEs (50)

  • CVE-2024-36694HigDec 18, 2024
    risk 0.40cvss 7.2epss 0.01

    OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.

  • CVE-2016-10509HigAug 31, 2017
    risk 0.40cvss 7.2epss 0.01

    SQL injection vulnerability in the updateAmazonOrderTracking function in upload/admin/model/openbay/amazon.php in OpenCart before version 2.3.0.0 allows remote authenticated administrators to execute arbitrary SQL commands via a carrier (aka courier_id) parameter to openbay.php.

  • CVE-2013-1891MedJun 24, 2022
    risk 0.39cvss 6.5epss 0.06

    In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed.

  • CVE-2020-10596MedMar 17, 2020
    risk 0.38cvss 5.4epss 0.03

    OpenCart 3.0.3.2 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section.

  • CVE-2018-25336MedMay 17, 2026
    risk 0.34cvss 5.3epss 0.00

    jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information without authentication. Attackers can craft malicious HTML forms targeting endpoints , and to change user credentials, passwords, and affiliate…

  • CVE-2021-47946MedMay 10, 2026
    risk 0.34cvss 5.3epss 0.00

    OpenCart 3.0.3.6 contains a cross-site request forgery vulnerability in the /account/edit endpoint that allows unauthenticated attackers to modify victim account details by tricking users into visiting malicious pages. Attackers can craft CSRF payloads that change victim email…

  • CVE-2020-29471MedDec 29, 2020
    risk 0.34cvss 4.8epss 0.01

    OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Profile Image. An admin can upload a profile image as a malicious code using JavaScript. Whenever anyone will see the profile picture, the code will execute and XSS will trigger.

  • CVE-2020-29470MedDec 29, 2020
    risk 0.34cvss 4.8epss 0.02

    OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Subject field of mail. This vulnerability can allow an attacker to inject the XSS payload in the Subject field of the mail and each time any user will open that mail of the website, the XSS triggers and the…

  • CVE-2019-15081MedAug 15, 2019
    risk 0.34cvss 4.8epss 0.02

    OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing feature of the Categories, Product, and Information pages.

  • CVE-2015-4671MedJan 12, 2016
    risk 0.33cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in OpenCart before 2.1.0.2 allows remote attackers to inject arbitrary web script or HTML via the zone_id parameter to index.php.

  • CVE-2021-37823MedNov 3, 2022
    risk 0.32cvss 4.9epss 0.01

    OpenCart 3.0.3.7 allows users to obtain database information or read server files through SQL injection in the background.

  • CVE-2018-11495MedMay 26, 2018
    risk 0.32cvss 4.9epss 0.02

    OpenCart through 3.0.2.0 allows directory traversal in the editDownload function in admin\model\catalog\download.php via admin/index.php?route=catalog/download/edit, related to the download_id. For example, an attacker can download ../../config.php.

  • CVE-2026-5331MedApr 2, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was determined in OpenCart 4.1.0.3. This affects an unknown part of the file installer.php of the component Extension Installer Page. Executing a manipulation can lead to path traversal. The attack may be launched remotely. The exploit has been publicly disclosed…

  • CVE-2026-3714MedMar 8, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability has been found in OpenCart 4.0.2.3. Affected by this issue is the function Save of the file admin/controller/design/template.php of the component Incomplete Fix CVE-2024-36694. Such manipulation leads to improper neutralization of special elements used in a…

  • CVE-2025-1749MedFeb 28, 2025
    risk 0.31cvss 4.7epss 0.00

    HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/voucher.

  • CVE-2025-1748MedFeb 28, 2025
    risk 0.31cvss 4.7epss 0.00

    HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/register.

  • CVE-2025-1747MedFeb 28, 2025
    risk 0.31cvss 4.7epss 0.00

    HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/login.

  • CVE-2020-13980MedJun 9, 2020
    risk 0.31cvss 4.8epss 0.01

    OpenCart 3.0.3.3 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section because of a lack of entity encoding. NOTE: this issue exists because of an incomplete fix for CVE-2020-10596. The vendor states "this is not a…

  • CVE-2021-47953MedMay 10, 2026
    risk 0.28cvss 4.3epss 0.00

    OpenCart 3.0.3.7 contains a cross-site request forgery vulnerability that allows attackers to change user passwords by sending crafted requests to the account/password endpoint. Attackers can trick authenticated users into submitting hidden forms with new password values in the…

  • CVE-2025-15116LowDec 28, 2025
    risk 0.24cvss 3.7epss 0.00

    A security flaw has been discovered in OpenCart up to 4.1.0.3. Affected by this issue is some unknown functionality of the component Single-Use Coupon Handler. Performing a manipulation results in race condition. The attack may be initiated remotely. The attack's complexity is…