VYPR

Opencart

by Opencart

Source repositories

CVEs (50)

  • CVE-2020-28838LowDec 11, 2020
    risk 0.23cvss 3.5epss 0.00

    Cross Site Request Forgery (CSRF) in CART option in OpenCart Ltd. Opencart CMS 3.0.3.6 allows attacker to add cart items via Add to cart.

  • CVE-2024-21517MedJun 22, 2024
    risk 0.20cvss 4.2epss 0.00

    This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the redirect parameter of customer account/login route. An attacker can inject arbitrary HTML and Javascript into the page response. As this vulnerability is present in…

  • CVE-2024-21516MedJun 22, 2024
    risk 0.20cvss 4.2epss 0.00

    This affects versions of the package opencart/opencart from 4.0.0.0 and before 4.1.0.0. A reflected XSS issue was identified in the directory parameter of admin common/filemanager.list route. An attacker could obtain a user's token by tricking the user to click on a maliciously…

  • CVE-2024-21515MedJun 22, 2024
    risk 0.20cvss 4.2epss 0.00

    This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the filename parameter of the admin tool/log route. An attacker could obtain a user's token by tricking the user to click on a maliciously crafted URL. The user is then…

  • CVE-2009-1621May 12, 2009
    risk 0.04cvss epss 0.06

    Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the route parameter.

  • CVE-2011-3763Sep 24, 2011
    risk 0.00cvss epss 0.02

    OpenCart 1.4.9.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/startup.php and certain other files.

  • CVE-2010-1610Apr 29, 2010
    risk 0.00cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in index.php in OpenCart 1.4 allows remote attackers to hijack the authentication of an application administrator for requests that create an administrative account via a POST request with the route parameter set to…

  • CVE-2010-0956Mar 10, 2010
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in index.php in OpenCart 1.3.2 allows remote attackers to execute arbitrary SQL commands via the page parameter.

  • CVE-2009-1027Mar 20, 2009
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in OpenCart 1.1.8 allows remote attackers to execute arbitrary SQL commands via the order parameter.

  • CVE-2008-3130Jul 10, 2008
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in OpenCart 0.7.7 allow remote attackers to inject arbitrary web script or HTML via the (1) firstname and (2) search parameters. NOTE: the provenance of this information is unknown; the details are obtained solely…

Page 3 of 3