Vulnerabilities > Opencart > High

DATE CVE VULNERABILITY TITLE RISK
2024-06-22 CVE-2024-21514 SQL Injection vulnerability in Opencart 3.0.3.9
This affects versions of the package opencart/opencart from 0.0.0.
network
high complexity
opencart CWE-89
8.1
2024-06-22 CVE-2024-21518 Path Traversal vulnerability in Opencart
This affects versions of the package opencart/opencart from 4.0.0.0.
network
low complexity
opencart CWE-22
7.2
2024-06-22 CVE-2024-21519 Unspecified vulnerability in Opencart
This affects versions of the package opencart/opencart from 4.0.0.0.
network
low complexity
opencart
7.2
2023-11-15 CVE-2023-47444 Code Injection vulnerability in Opencart
An issue discovered in OpenCart 4.0.0.0 to 4.0.2.3 allows authenticated backend users having common/security write privilege can write arbitrary untrusted data inside config.php and admin/config.php, resulting in remote code execution on the underlying server.
network
low complexity
opencart CWE-94
8.8
2023-09-27 CVE-2023-2315 Path Traversal vulnerability in Opencart
Path Traversal in OpenCart versions 4.0.0.0 to 4.0.2.2 allows an authenticated user with access/modify privilege on the Log component to empty out arbitrary files on the server
network
low complexity
opencart CWE-22
8.8
2023-06-20 CVE-2020-20491 SQL Injection vulnerability in Opencart
SQL injection vulnerability in OpenCart v.2.2.00 thru 3.0.3.2 allows a remote attacker to execute arbitrary code via the Fba plugin function in upload/admin/index.php.
network
low complexity
opencart CWE-89
7.2
2018-07-02 CVE-2018-13067 Cross-Site Request Forgery (CSRF) vulnerability in Opencart
/upload/catalog/controller/account/password.php in OpenCart through 3.0.2.0 has CSRF via the index.php?route=account/password URI to change a user's password.
network
low complexity
opencart CWE-352
8.8
2018-05-26 CVE-2018-11494 Unrestricted Upload of File with Dangerous Type vulnerability in Opencart
The "program extension upload" feature in OpenCart through 3.0.2.0 has a six-step process (upload, install, unzip, move, xml, remove) that allows attackers to execute arbitrary code if the remove step is skipped, because the attacker can discover a secret temporary directory name (containing 10 random digits) via a directory traversal attack involving language_info['code'].
network
high complexity
opencart CWE-434
8.0
2017-08-31 CVE-2016-10509 SQL Injection vulnerability in Opencart
SQL injection vulnerability in the updateAmazonOrderTracking function in upload/admin/model/openbay/amazon.php in OpenCart before version 2.3.0.0 allows remote authenticated administrators to execute arbitrary SQL commands via a carrier (aka courier_id) parameter to openbay.php.
network
low complexity
opencart CWE-89
7.2