Known Vulnerabilities for Opencart by Simple Machines
Listed below are 1 of the newest known vulnerabilities associated with "Opencart" by "Simple Machines".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-47953 json | OpenCart 3.0.3.7 contains a cross-site request forgery vulnerability that allows attackers to change user passwords by sendin... | Not Provided | 2026-05-10 | 2026-05-11 |
| CVE-2021-47946 json | OpenCart 3.0.3.6 contains a cross-site request forgery vulnerability in the /account/edit endpoint that allows unauthenticate... | Not Provided | 2026-05-10 | 2026-05-12 |
| CVE-2021-47928 json | Opencart TMD Vendor System 3.x contains a blind SQL injection vulnerability that allows unauthenticated attackers to extract ... | Not Provided | 2026-05-10 | 2026-05-11 |
| CVE-2021-47923 json | OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting arbitra... | Not Provided | 2026-05-10 | 2026-05-11 |
| CVE-2018-25336 json | jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account i... | Not Provided | 2026-05-17 | 2026-05-25 |
| CVE-2017-20282 json | Joomla! Component jCart for OpenCart 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to man... | Not Provided | 2026-06-19 | 2026-06-22 |
| CVE-2008-3130 json | Not Provided | 2008-07-10 | 2026-04-23 |