CVE-2019-15081: Opencart

Medium severity, CVSS 4.8. EPSS: 2% chance of exploitation in the next 30 days.

OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing feature of the Categories, Product, and Information pages.

Affected products

  • Opencart Opencart: from 3.0.0.0, up to and including 3.0.3.2

Published 2019-08-15. Last modified 2026-06-17.