Feed live

OpenCart vulnerabilities - every known CVE affecting the platform

OpenCart powers a large number of small and mid-sized storefronts, where unpatched core or extension vulnerabilities often go unnoticed the longest.

Total CVEs tracked
347,287
All time
Critical · Active
11,990
CVSS ≥ 9.0
New · 14 days
2,743
Newly disclosed
Feed last synced
2 hrs ago
Data freshness

opencart security

Every published CVE affecting opencart

This list contains every CVE that names opencart as an affected product. Records come from the official CVE feeds maintained by MITRE and NIST. Each record includes a CVSS severity score, the affected version range, and a link to the full NVD entry. New records usually appear here within minutes of publication.

Third-party plugins, extensions, and add-ons built on top of opencart are included alongside the core product. In most CMS ecosystems, the majority of CVEs come from the extension layer rather than the core application itself. Searching by component name is just as important as searching by platform name.

Understanding CVSS scores

Severity ratings explained

Every CVE has a CVSS 3.x score from 0 to 10. The score is based on how the vulnerability can be reached (over the network or locally), how complex the exploit is, what access an attacker needs beforehand, whether a victim has to do something first, and the impact on confidentiality, integrity, and availability if the attack succeeds.

Critical 9.0–10.0 Remote, no auth, max impact
High 7.0–8.9 Serious, remotely exploitable
Medium 4.0–6.9 Often requires auth or conditions
Low 0.1–3.9 Limited exploitability or impact

Search by component name, vendor, or keyword to filter this list. Click any CVE ID to see the full record. If your installed version falls within the affected range, update immediately or check the vendor's security advisory.