Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/opencart/opencart

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

OpenCart version 4.2.0.0 contains a directory traversal vulnerability in its extension installer. The installer extracts uploaded .zip extension files without validating that extracted paths remain within the intended directory. This allows an attacker who can upload a malicious extension to write files outside the intended directory, such as placing a PHP web shell in the webroot. Exploitation requires valid administrator credentials to install the malicious extension. No patch is currently available, and users are advised to avoid installing untrusted extensions and to run OpenCart with minimal privileges.

Join the discussion
0

CVE-2026-5331 is a medium severity path traversal vulnerability in OpenCart version 4.1.0.3, specifically in the Extension Installer Page's installer.php file. This vulnerability allows an attacker with high privileges to remotely manipulate file paths, potentially accessing unauthorized files. The vulnerability has been publicly disclosed, but no vendor response or patch is currently available. Exploitation requires high privileges, and the impact is limited by low confidentiality, integrity, and availability requirements. No known exploits are reported in the wild at this time.

Join the discussion

OpenCart Core 4.0.2.3 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'search' parameter. Attackers can send GET requests to the product search endpoint with malicious 'search' values to extract sensitive database information using boolean-based blind or time-based blind SQL injection techniques.

Join the discussion
CVE-2025-45892: n/aCVE-2025-45892
0

OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via the blog editor. The vulnerability arises because input in the blog's editor is not properly sanitized or escaped before being rendered. This allows attackers to inject malicious JavaScript code

Join the discussion

Showing 1 to 4 of 4 results

Filters:Package: pkg:github/opencart/opencart
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses