Opencart is a widely deployed open-source e-commerce platform whose vulnerability footprint concentrates in a single product serving small to medium-sized online retailers and merchants. The vendor's disclosures recur across classic application-layer input-handling weaknesses, including cross-site scripting, SQL injection, path traversal, cross-site request forgery, and code injection, reflecting the web-application nature of the platform and the challenge of maintaining security across a distributed plugin ecosystem. Vulnerabilities affecting Opencart frequently acquire public exploit code, making disclosed flaws actionable to attackers relatively quickly. Defenders should treat Opencart installations as a patching priority, particularly internet-facing storefronts, and monitor both core platform releases and the security posture of deployed extensions; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opencart over time
Signals from CVEs in this vendor scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-1891MEDIUM In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed. | Jun 24, 2022 | 6.5 | 35 | NO | YES |
CVE-2024-21514HIGH This affects versions of the package opencart/opencart from 0.0.0. An SQL Injection issue was identified in the Divido payment extension for OpenCart, which is included by default | Jun 22, 2024 | 8.1 | 33 | NO | NO |
CVE-2024-58341HIGH OpenCart Core 4.0.2.3 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'search' paramet | Mar 25, 2026 | 8.2 | 28 | NO | NO |
CVE-2019-15081MEDIUM OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing feature of the Categories, Product, and Information pages. | Aug 15, 2019 | 4.8 | 28 | NO | YES |
CVE-2014-3990CRITICAL The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forgery (SSRF) attacks or possibly co | Mar 20, 2018 | 9.8 | 27 | NO | NO |
CVE-2023-2315HIGH Path Traversal in OpenCart versions 4.0.0.0 to 4.0.2.2 allows an authenticated user with access/modify privilege on the Log component to empty out arbitrary files on the server | Sep 27, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-40834CRITICAL OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated attackers to gain access to the app | Sep 12, 2023 | 9.8 | 26 | NO | NO |
CVE-2020-29470MEDIUM OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Subject field of mail. This vulnerability can allow an attacker to inject the XSS payload in the Subject field of | Dec 29, 2020 | 4.8 | 25 | NO | YES |
CVE-2018-13067HIGH /upload/catalog/controller/account/password.php in OpenCart through 3.0.2.0 has CSRF via the index.php?route=account/password URI to change a user's password. | Jul 2, 2018 | 8.8 | 25 | NO | NO |
CVE-2009-1621MEDIUM Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the route parameter. | May 12, 2009 | 5.0 | 25 | NO | YES |
Signals from CVEs in this vendor scope (39 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opencart.
Media articles that mention a CVE ID that affects a product developed by Opencart — matched by CVE ID, not by vendor name.