Sale of a 0-day exploit for unauthenticated SQL Injection in the OpenCart plugin
Dark Web2026-07-01, 12:40
For informational purposes only
Vulnerable versions: OpenCart 2.x, 3.x and 4.x
Type of vulnerability: unauthenticated SQL Injection
Price: auction (start — $100, step — $100, blitz — $1000)
The author announces the sale of an SQL injection in a plugin for OpenCart. The plugin was created on March 19, 2019, and the last update was on June 26, 2026, with 169 sales.
OpenCart — a popular open-source CMS for online stores, especially in the small and medium e-commerce segment. According to BuiltWith, there are about 190 thousand active sites on OpenCart worldwide and more than 922 thousand sites that have used the platform historically.
Vendors
Products