Junglewise Threat Intelligence

CVE-2026-84438: OpenCart stored XSS in customer profile fields

CVE-2026-84438 · Severity: low · CVSS 3.5 · Published 2026-09-02

Technologies: OpenCart. Vendors: OpenCart.

Executive brief

OpenCart is an open-source e-commerce platform used to build online stores. A vulnerability allows regular customers to inject malicious HTML code into their account profile fields (such as first name), which is then executed in administrators' browsers when they manage orders or customer returns. An attacker could steal admin session tokens, modify orders, or compromise customer data.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in OpenCart's customer account management and admin order/return workflows. The root cause is improper output encoding in the admin backend: customer-supplied firstname/lastname values are stored in the database without sanitization (catalog/controller/account/edit.php), retrieved by the admin autocomplete API, entity-encoded, then decoded and injected into HTML via JavaScript string concatenation and .html() calls (admin/view/javascript/common.js, admin/view/template/sale/order_info.twig). An unauthenticated attacker requires only a normal front-office customer account; they inject payload in their profile, and when an admin opens the order or returns workflow and selects that customer, the JavaScript executes in the admin's browser context. No patch has been made available despite early vendor notification.

Affected products

  • OpenCart OpenCart 4.1.0.3, 4.1.0.4

Timeline

  • 2026-09-02: disclosed: Publicly disclosed; vendor did not respond to early notification

References

Related threats