Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-11494

23
FAUCET Score

CVE-2018-11494 describes a critical arbitrary code execution vulnerability in OpenCart through version 3.0.2.0, specifically within its "program extension upload" feature. Attackers with high privileges can exploit a directory traversal flaw to discover a secret temporary directory. This allows them to bypass the final removal step of the extension upload process, leaving malicious code on the server. The vulnerability carries a high CVSS score of 8.0 due to its network-based attack vector, high impact on confidentiality, integrity, and availability, and the potential for complete system compromise. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 3.0.2.0CPE matchmatch criteria
cpe:2.3:a:opencart:opencart:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

8.0HIGH

CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.3
Impact Score
6.0
CvssVersion
3.0

Exploit Intelligence

EPSS Score
2.38%
Probability of exploitation in next 30 days
EPSS Percentile
82.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0238 is in the 88th percentile among its peer group of 81 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

composerGHSA-wx3q-f5f2-4q8vhigh

OpenCart Path Traversal

May 14, 2022

References

bigdiao.cc / 2018/05/24/Opencart-v3-0-2-0
ExploitThird Party Advisory