Opencart

Opencart

43 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.1%
  • Veröffentlicht 02.04.2026 13:00:13
  • Zuletzt bearbeitet 03.04.2026 16:10:52

A vulnerability was determined in OpenCart 4.1.0.3. This affects an unknown part of the file installer.php of the component Extension Installer Page. Executing a manipulation can lead to path traversal. The attack may be launched remotely. The exploi...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 25.03.2026 16:16:07
  • Zuletzt bearbeitet 27.03.2026 19:24:38

OpenCart Core 4.0.2.3 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'search' parameter. Attackers can send GET requests to the product search endpoint wit...

  • EPSS 0.07%
  • Veröffentlicht 08.03.2026 06:32:06
  • Zuletzt bearbeitet 09.03.2026 18:37:31

A vulnerability has been found in OpenCart 4.0.2.3. Affected by this issue is the function Save of the file admin/controller/design/template.php of the component Incomplete Fix CVE-2024-36694. Such manipulation leads to improper neutralization of spe...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 28.12.2025 02:02:06
  • Zuletzt bearbeitet 24.02.2026 07:16:57

A security flaw has been discovered in OpenCart up to 4.1.0.3. Affected by this issue is some unknown functionality of the component Single-Use Coupon Handler. Performing a manipulation results in race condition. The attack may be initiated remotely....

  • EPSS 0.04%
  • Veröffentlicht 25.07.2025 17:15:32
  • Zuletzt bearbeitet 07.08.2025 01:31:40

OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via SVG file uploads used in blog posts. The vulnerability arises because SVG files uploaded through the media manager are not properly sanitized. Attackers can craf...

  • EPSS 0.05%
  • Veröffentlicht 25.07.2025 17:15:32
  • Zuletzt bearbeitet 07.08.2025 14:19:07

OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via the blog editor. The vulnerability arises because input in the blog's editor is not properly sanitized or escaped before being rendered. This allows attackers to...

  • EPSS 0.12%
  • Veröffentlicht 28.02.2025 14:15:35
  • Zuletzt bearbeitet 07.05.2025 19:49:23

HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/voucher.

  • EPSS 0.12%
  • Veröffentlicht 28.02.2025 14:15:35
  • Zuletzt bearbeitet 07.05.2025 19:47:43

HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/register.

  • EPSS 0.12%
  • Veröffentlicht 28.02.2025 14:15:35
  • Zuletzt bearbeitet 07.05.2025 19:47:20

HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/login.

  • EPSS 0.11%
  • Veröffentlicht 28.02.2025 14:15:34
  • Zuletzt bearbeitet 07.05.2025 19:47:12

Cross-Site Scripting vulnerability in OpenCart versions prior to 4.1.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the search in the /product/search endpoint. T...