{"schema_version":1,"title":"OpenCart vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 8 vulnerabilities in OpenCart: 0 in the last 7 days and 3 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-84438, was published on 2 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/opencart","json_url":"https://junglewise.ai/threats/vendors/opencart.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/opencart","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":1,"all_time":8,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":2,"last_90_days":3,"last_365_days":8},"latest":[{"cve":"CVE-2026-84438","cvss":3.5,"epss":0.0033,"slug":"cve-2026-84438-opencart-stored-xss-in-customer-profile-fields","title":"OpenCart stored XSS in customer profile fields","severity":"low","exploited":false,"published_at":"2026-09-02T02:17:20.27+00:00","url":"https://junglewise.ai/threats/cve-2026-84438-opencart-stored-xss-in-customer-profile-fields"},{"cve":"CVE-2026-84437","cvss":3.5,"epss":0.0033,"slug":"cve-2026-84437-opencart-stored-cross-site-scripting-in-customer-address","title":"OpenCart stored cross-site scripting in customer address","severity":"low","exploited":false,"published_at":"2026-09-02T02:17:20.087+00:00","url":"https://junglewise.ai/threats/cve-2026-84437-opencart-stored-cross-site-scripting-in-customer-address"},{"cve":"CVE-2026-18412","cvss":9.1,"epss":0.0054,"slug":"cve-2026-18412-opencart-path-traversal-in-extension-installer","title":"OpenCart path traversal in extension installer","severity":"critical","exploited":false,"published_at":"2026-08-10T15:17:42.467+00:00","url":"https://junglewise.ai/threats/cve-2026-18412-opencart-path-traversal-in-extension-installer"},{"cve":"CVE-2017-20282","cvss":8.2,"slug":"cve-2017-20282-soft-php-jcart-for-opencart-sql-injection-in-product-id","title":"Soft-Php jCart for OpenCart SQL injection in product_id","severity":"high","exploited":false,"published_at":"2026-06-19T17:16:16.557+00:00","url":"https://junglewise.ai/threats/cve-2017-20282-soft-php-jcart-for-opencart-sql-injection-in-product-id"},{"cve":"CVE-2018-25336","cvss":5.3,"slug":"cve-2018-25336-softphp-jcart-for-opencart-csrf-in-account-management-endpoints","title":"softPHP jCart for OpenCart CSRF in account management endpoints","severity":"medium","exploited":false,"published_at":"2026-05-17T13:16:45.343+00:00","url":"https://junglewise.ai/threats/cve-2018-25336-softphp-jcart-for-opencart-csrf-in-account-management-endpoints"},{"cve":"CVE-2021-47953","cvss":4.3,"epss":0.0013,"slug":"cve-2021-47953-opencart-csrf-password-change-in-account-password-endpoint","title":"OpenCart CSRF password change in account/password endpoint","severity":"medium","exploited":false,"published_at":"2026-05-10T13:16:31.853+00:00","url":"https://junglewise.ai/threats/cve-2021-47953-opencart-csrf-password-change-in-account-password-endpoint"},{"cve":"CVE-2021-47946","cvss":5.3,"epss":0.0015,"slug":"cve-2021-47946-opencart-csrf-in-account-edit-endpoint","title":"OpenCart CSRF in account edit endpoint","severity":"medium","exploited":false,"published_at":"2026-05-10T13:16:31.027+00:00","url":"https://junglewise.ai/threats/cve-2021-47946-opencart-csrf-in-account-edit-endpoint"},{"cve":"CVE-2021-47923","cvss":9.8,"epss":0.0042,"slug":"cve-2021-47923-opencart-session-fixation-in-ocsessid-cookie","title":"OpenCart session fixation in OCSESSID cookie","severity":"critical","exploited":false,"published_at":"2026-05-10T13:16:28.17+00:00","url":"https://junglewise.ai/threats/cve-2021-47923-opencart-session-fixation-in-ocsessid-cookie"}],"vendor":{"hub":true,"name":"OpenCart","slug":"opencart","homepage":"https://www.opencart.com/","description":"An open-source e-commerce platform for online merchants.","url":"https://junglewise.ai/threats/vendors/opencart"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2021-47923","cvss":9.8,"epss":0.0042,"slug":"cve-2021-47923-opencart-session-fixation-in-ocsessid-cookie","title":"OpenCart session fixation in OCSESSID cookie","severity":"critical","exploited":false,"published_at":"2026-05-10T13:16:28.17+00:00","url":"https://junglewise.ai/threats/cve-2021-47923-opencart-session-fixation-in-ocsessid-cookie"},{"cve":"CVE-2026-18412","cvss":9.1,"epss":0.0054,"slug":"cve-2026-18412-opencart-path-traversal-in-extension-installer","title":"OpenCart path traversal in extension installer","severity":"critical","exploited":false,"published_at":"2026-08-10T15:17:42.467+00:00","url":"https://junglewise.ai/threats/cve-2026-18412-opencart-path-traversal-in-extension-installer"},{"cve":"CVE-2017-20282","cvss":8.2,"slug":"cve-2017-20282-soft-php-jcart-for-opencart-sql-injection-in-product-id","title":"Soft-Php jCart for OpenCart SQL injection in product_id","severity":"high","exploited":false,"published_at":"2026-06-19T17:16:16.557+00:00","url":"https://junglewise.ai/threats/cve-2017-20282-soft-php-jcart-for-opencart-sql-injection-in-product-id"},{"cve":"CVE-2021-47946","cvss":5.3,"epss":0.0015,"slug":"cve-2021-47946-opencart-csrf-in-account-edit-endpoint","title":"OpenCart CSRF in account edit endpoint","severity":"medium","exploited":false,"published_at":"2026-05-10T13:16:31.027+00:00","url":"https://junglewise.ai/threats/cve-2021-47946-opencart-csrf-in-account-edit-endpoint"},{"cve":"CVE-2018-25336","cvss":5.3,"slug":"cve-2018-25336-softphp-jcart-for-opencart-csrf-in-account-management-endpoints","title":"softPHP jCart for OpenCart CSRF in account management endpoints","severity":"medium","exploited":false,"published_at":"2026-05-17T13:16:45.343+00:00","url":"https://junglewise.ai/threats/cve-2018-25336-softphp-jcart-for-opencart-csrf-in-account-management-endpoints"},{"cve":"CVE-2021-47953","cvss":4.3,"epss":0.0013,"slug":"cve-2021-47953-opencart-csrf-password-change-in-account-password-endpoint","title":"OpenCart CSRF password change in account/password endpoint","severity":"medium","exploited":false,"published_at":"2026-05-10T13:16:31.853+00:00","url":"https://junglewise.ai/threats/cve-2021-47953-opencart-csrf-password-change-in-account-password-endpoint"},{"cve":"CVE-2026-84438","cvss":3.5,"epss":0.0033,"slug":"cve-2026-84438-opencart-stored-xss-in-customer-profile-fields","title":"OpenCart stored XSS in customer profile fields","severity":"low","exploited":false,"published_at":"2026-09-02T02:17:20.27+00:00","url":"https://junglewise.ai/threats/cve-2026-84438-opencart-stored-xss-in-customer-profile-fields"},{"cve":"CVE-2026-84437","cvss":3.5,"epss":0.0033,"slug":"cve-2026-84437-opencart-stored-cross-site-scripting-in-customer-address","title":"OpenCart stored cross-site scripting in customer address","severity":"low","exploited":false,"published_at":"2026-09-02T02:17:20.087+00:00","url":"https://junglewise.ai/threats/cve-2026-84437-opencart-stored-cross-site-scripting-in-customer-address"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"OpenCart","slug":"opencart","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/opencart"}]}