CVE-2023-40834: Opencart
Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.
OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated attackers to gain access to the application via a brute force attack to the password parameter.
Affected products
- Opencart Opencart: version 4.0.2.2 only
Published 2023-09-12. Last modified 2026-06-17.