Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
opencart opencart vulnerabilities and exploits
(subscribe to this query)
7.2
CVSSv3
CVE-2020-20491
SQL injection vulnerability in OpenCart v.2.2.00 thru 3.0.3.2 allows a remote malicious user to execute arbitrary code via the Fba plugin function in upload/admin/index.php.
Opencart Opencart
9.8
CVSSv3
CVE-2023-40834
OpenCart CMS v4.0.2.2 exists to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated malicious users to gain access to the application via a brute force attack to the password parameter.
Opencart Opencart 4.0.2.2
4.8
CVSSv3
CVE-2020-13980
OpenCart 3.0.3.3 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section because of a lack of entity encoding. NOTE: this issue exists because of an incomplete fix for CVE-2020-10596. The vendor states "this is ...
Opencart Opencart 3.0.3.3
NA
CVE-2011-3763
OpenCart 1.4.9.3 allows remote malicious users to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/startup.php and certain other files.
Opencart Opencart 1.4.9.3
NA
CVE-2010-0956
SQL injection vulnerability in index.php in OpenCart 1.3.2 allows remote malicious users to execute arbitrary SQL commands via the page parameter.
Opencart Opencart 1.3.2
4.8
CVSSv3
CVE-2020-29470
OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Subject field of mail. This vulnerability can allow an malicious user to inject the XSS payload in the Subject field of the mail and each time any user will open that mail of the website, the XSS triggers and the a...
Opencart Opencart 3.0.3.6
4.8
CVSSv3
CVE-2020-29471
OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Profile Image. An admin can upload a profile image as a malicious code using JavaScript. Whenever anyone will see the profile picture, the code will execute and XSS will trigger.
Opencart Opencart 3.0.3.6
3.5
CVSSv3
CVE-2020-28838
Cross Site Request Forgery (CSRF) in CART option in OpenCart Ltd. Opencart CMS 3.0.3.6 allows malicious user to add cart items via Add to cart.
Opencart Opencart 3.0.3.6
5.4
CVSSv3
CVE-2020-10596
OpenCart 3.0.3.2 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section.
Opencart Opencart 3.0.3.2
2 Github repositories
NA
CVE-2009-1621
Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote malicious users to read arbitrary files via a .. (dot dot) in the route parameter.
Opencart Opencart 1.1.8
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-21991
CVE-2024-32674
path traversal
CVE-2023-21987
denial of service
dos
CVE-2024-4647
CVE-2024-25519
CVE-2024-33612
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »