PT-2026-84585 · Opencart · Opencart

·

CVE-2026-84437

·

Published

2026-09-02

·

Updated

2026-09-03

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions OpenCart versions 4.1.0.3 through 4.1.0.4
Description An issue exists in the Autocomplete Workflow component within the file catalog/controller/account/address.php. Remote manipulation of the address 1 argument allows for cross site scripting, a technique where malicious scripts are injected into trusted websites.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Restrict the use of the address 1 argument in the catalog/controller/account/address.php file to minimize the risk of exploitation.

Exploit

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84437

Affected Products

Opencart