๐Ÿ” CVE Alert

CVE-2026-18412

UNKNOWN 0.0

The OpenCart v4.2.0.0 extension installer contains a directory traversal vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 extension installer extracts these zip files, but does not validate that the extracted paths stay inside the intended extraction directory. An attacker can craft a malicious extension containing file path traversal sequences, such as ../. With this vulnerability, an attacker can write files, such as a PHP web shell, into the webroot directory.

Vendor opencart
Product opencart
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for opencart opencart

Be the first to know when new unknown vulnerabilities affecting opencart opencart are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

OpenCart / OpenCart
4.2.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
kb.cert.org: https://kb.cert.org/vuls/id/614868