CVE-2025-15116
- EPSS 0.06%
- Veröffentlicht 28.12.2025 02:02:06
- Zuletzt bearbeitet 24.02.2026 07:16:57
A security flaw has been discovered in OpenCart up to 4.1.0.3. Affected by this issue is some unknown functionality of the component Single-Use Coupon Handler. Performing a manipulation results in race condition. The attack may be initiated remotely....
CVE-2025-45893
- EPSS 0.03%
- Veröffentlicht 25.07.2025 17:15:32
- Zuletzt bearbeitet 07.08.2025 01:31:40
OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via SVG file uploads used in blog posts. The vulnerability arises because SVG files uploaded through the media manager are not properly sanitized. Attackers can craf...
CVE-2025-45892
- EPSS 0.03%
- Veröffentlicht 25.07.2025 17:15:32
- Zuletzt bearbeitet 07.08.2025 14:19:07
OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via the blog editor. The vulnerability arises because input in the blog's editor is not properly sanitized or escaped before being rendered. This allows attackers to...
CVE-2025-1749
- EPSS 0.08%
- Veröffentlicht 28.02.2025 14:15:35
- Zuletzt bearbeitet 07.05.2025 19:49:23
HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/voucher.
CVE-2025-1748
- EPSS 0.08%
- Veröffentlicht 28.02.2025 14:15:35
- Zuletzt bearbeitet 07.05.2025 19:47:43
HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/register.
CVE-2025-1747
- EPSS 0.08%
- Veröffentlicht 28.02.2025 14:15:35
- Zuletzt bearbeitet 07.05.2025 19:47:20
HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/login.
CVE-2025-1746
- EPSS 0.07%
- Veröffentlicht 28.02.2025 14:15:34
- Zuletzt bearbeitet 07.05.2025 19:47:12
Cross-Site Scripting vulnerability in OpenCart versions prior to 4.1.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the search in the /product/search endpoint. T...
CVE-2025-0580
- EPSS 0.11%
- Veröffentlicht 20.01.2025 03:15:08
- Zuletzt bearbeitet 20.01.2025 03:15:08
A vulnerability was found in Shiprocket Module 3 on OpenCart. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?route=extension/module/rest_api&action=getOrders of the component REST API Module...
CVE-2025-0579
- EPSS 0.07%
- Veröffentlicht 20.01.2025 03:15:08
- Zuletzt bearbeitet 20.01.2025 03:15:08
A vulnerability was found in Shiprocket Module 3/4 on OpenCart. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /index.php?route=extension/shiprocket/module/restapi of the component REST API Mo...
CVE-2025-0460
- EPSS 0.2%
- Veröffentlicht 14.01.2025 16:15:34
- Zuletzt bearbeitet 14.01.2025 16:15:34
A vulnerability, which was classified as critical, was found in Blog Botz for Journal Theme 1.0 on OpenCart. This affects an unknown part of the file /index.php?route=extension/module/blog_add. The manipulation of the argument image leads to unrestri...