Opencart

Opencart

43 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Veröffentlicht 20.01.2025 03:15:08
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A vulnerability was found in Shiprocket Module 3 on OpenCart. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?route=extension/module/rest_api&action=getOrders of the component REST API Module...

  • EPSS 0.07%
  • Veröffentlicht 20.01.2025 03:15:08
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A vulnerability was found in Shiprocket Module 3/4 on OpenCart. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /index.php?route=extension/shiprocket/module/restapi of the component REST API Mo...

  • EPSS 0.18%
  • Veröffentlicht 14.01.2025 16:15:34
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A vulnerability, which was classified as critical, was found in Blog Botz for Journal Theme 1.0 on OpenCart. This affects an unknown part of the file /index.php?route=extension/module/blog_add. The manipulation of the argument image leads to unrestri...

Exploit
  • EPSS 0.72%
  • Veröffentlicht 18.12.2024 20:15:22
  • Zuletzt bearbeitet 22.04.2025 15:36:02

OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.

Exploit
  • EPSS 0.28%
  • Veröffentlicht 22.06.2024 05:15:11
  • Zuletzt bearbeitet 21.11.2024 08:54:36

This affects versions of the package opencart/opencart from 4.0.0.0. An Arbitrary File Creation issue was identified via the database restoration functionality. By injecting PHP code into the database, an attacker with admin privileges can create a b...

Exploit
  • EPSS 2.18%
  • Veröffentlicht 22.06.2024 05:15:11
  • Zuletzt bearbeitet 21.11.2024 08:54:36

This affects versions of the package opencart/opencart from 4.0.0.0. A Zip Slip issue was identified via the marketplace installer due to improper sanitization of the target path, allowing files within a malicious archive to traverse the filesystem a...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 22.06.2024 05:15:11
  • Zuletzt bearbeitet 14.01.2025 17:15:16

This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the redirect parameter of customer account/login route. An attacker can inject arbitrary HTML and Javascript into the page response. As this ...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 22.06.2024 05:15:10
  • Zuletzt bearbeitet 14.01.2025 17:15:15

This affects versions of the package opencart/opencart from 4.0.0.0 and before 4.1.0.0. A reflected XSS issue was identified in the directory parameter of admin common/filemanager.list route. An attacker could obtain a user's token by tricking the us...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 22.06.2024 05:15:10
  • Zuletzt bearbeitet 14.01.2025 17:15:15

This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the filename parameter of the admin tool/log route. An attacker could obtain a user's token by tricking the user to click on a maliciously cr...

Exploit
  • EPSS 46.49%
  • Veröffentlicht 22.06.2024 05:15:09
  • Zuletzt bearbeitet 21.11.2024 08:54:35

This affects versions of the package opencart/opencart from 0.0.0. An SQL Injection issue was identified in the Divido payment extension for OpenCart, which is included by default in version 3.0.3.9. As an anonymous unauthenticated user, if the Divid...