Loading HuntDB...

GHSA-fpvx-g24w-mpgm

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via the blog editor. The vulnerability arises because input in the blog's editor is not properly sanitized or escaped before being rendered. This allows attackers to inject malicious JavaScript code

Related CVEs

Key Information

GHSA ID
GHSA-fpvx-g24w-mpgm
Published
July 25, 2025 6:30 PM
Last Modified
July 25, 2025 9:33 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 26, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.