CVE-2023-40834: Opencart

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated attackers to gain access to the application via a brute force attack to the password parameter.

Affected products

Published 2023-09-12. Last modified 2026-06-17.