Opencart

Opencart

49 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 25.07.2025 17:15:32
  • Zuletzt bearbeitet 07.08.2025 14:19:07

OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via the blog editor. The vulnerability arises because input in the blog's editor is not properly sanitized or escaped before being rendered. This allows attackers to...

  • EPSS 0.25%
  • Veröffentlicht 25.07.2025 17:15:32
  • Zuletzt bearbeitet 07.08.2025 01:31:40

OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via SVG file uploads used in blog posts. The vulnerability arises because SVG files uploaded through the media manager are not properly sanitized. Attackers can craf...

  • EPSS 0.25%
  • Veröffentlicht 28.02.2025 14:15:35
  • Zuletzt bearbeitet 07.05.2025 19:49:23

HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/voucher.

  • EPSS 0.25%
  • Veröffentlicht 28.02.2025 14:15:35
  • Zuletzt bearbeitet 07.05.2025 19:47:43

HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/register.

  • EPSS 0.25%
  • Veröffentlicht 28.02.2025 14:15:35
  • Zuletzt bearbeitet 07.05.2025 19:47:20

HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/login.

  • EPSS 0.22%
  • Veröffentlicht 28.02.2025 14:15:34
  • Zuletzt bearbeitet 07.05.2025 19:47:12

Cross-Site Scripting vulnerability in OpenCart versions prior to 4.1.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the search in the /product/search endpoint. T...

  • EPSS 0.38%
  • Veröffentlicht 20.01.2025 03:15:08
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A vulnerability was found in Shiprocket Module 3 on OpenCart. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?route=extension/module/rest_api&action=getOrders of the component REST API Module...

  • EPSS 0.39%
  • Veröffentlicht 20.01.2025 03:15:08
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A vulnerability was found in Shiprocket Module 3/4 on OpenCart. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /index.php?route=extension/shiprocket/module/restapi of the component REST API Mo...

  • EPSS 0.45%
  • Veröffentlicht 14.01.2025 16:15:34
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A vulnerability, which was classified as critical, was found in Blog Botz for Journal Theme 1.0 on OpenCart. This affects an unknown part of the file /index.php?route=extension/module/blog_add. The manipulation of the argument image leads to unrestri...

Exploit
  • EPSS 0.9%
  • Veröffentlicht 18.12.2024 20:15:22
  • Zuletzt bearbeitet 22.04.2025 15:36:02

OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.