Sale of a 0-day exploit for unauthenticated SQL Injection in the OpenCart plugin

Dark Web2026-07-01, 12:40
For informational purposes only
Vulnerable versions: OpenCart 2.x, 3.x and 4.x Type of vulnerability: unauthenticated SQL Injection Price: auction (start — $100, step — $100, blitz — $1000)
The author announces the sale of an SQL injection in a plugin for OpenCart. The plugin was created on March 19, 2019, and the last update was on June 26, 2026, with 169 sales.
OpenCart — a popular open-source CMS for online stores, especially in the small and medium e-commerce segment. According to BuiltWith, there are about 190 thousand active sites on OpenCart worldwide and more than 922 thousand sites that have used the platform historically.
Vendors
Opencart
Builtwith
Products
Opencart
Opencart Plugin