VYPR

Vendor CVEs

Opencart

All CVEs

59 total · sorted by risk
  • CVE-2024-21517MedJun 22, 2024
    risk 0.20cvss 4.2epss 0.00

    This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the redirect parameter of customer account/login route. An attacker can inject arbitrary HTML and Javascript into the page response. As this vulnerability is present in…

  • CVE-2024-21516MedJun 22, 2024
    risk 0.20cvss 4.2epss 0.00

    This affects versions of the package opencart/opencart from 4.0.0.0 and before 4.1.0.0. A reflected XSS issue was identified in the directory parameter of admin common/filemanager.list route. An attacker could obtain a user's token by tricking the user to click on a maliciously…

  • CVE-2024-21515MedJun 22, 2024
    risk 0.20cvss 4.2epss 0.00

    This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the filename parameter of the admin tool/log route. An attacker could obtain a user's token by tricking the user to click on a maliciously crafted URL. The user is then…

  • CVE-2009-1621May 12, 2009
    risk 0.04cvss epss 0.06

    Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the route parameter.

  • CVE-2011-3763Sep 24, 2011
    risk 0.00cvss epss 0.02

    OpenCart 1.4.9.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/startup.php and certain other files.

  • CVE-2010-1610Apr 29, 2010
    risk 0.00cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in index.php in OpenCart 1.4 allows remote attackers to hijack the authentication of an application administrator for requests that create an administrative account via a POST request with the route parameter set to…

  • CVE-2010-0956Mar 10, 2010
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in index.php in OpenCart 1.3.2 allows remote attackers to execute arbitrary SQL commands via the page parameter.

  • CVE-2009-1027Mar 20, 2009
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in OpenCart 1.1.8 allows remote attackers to execute arbitrary SQL commands via the order parameter.

  • CVE-2008-3130Jul 10, 2008
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in OpenCart 0.7.7 allow remote attackers to inject arbitrary web script or HTML via the (1) firstname and (2) search parameters. NOTE: the provenance of this information is unknown; the details are obtained solely…

Page 2 of 2