VDB
CVE-2026-18412
CVE-2026-18412
PUBLISHED
CVSS 9.1 CRITICAL
Reported by certcc · Published August 10, 2026
OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 extension installer extracts these zip files, but does not validate that the extracted paths stay inside the intended extraction directory. An attacker can craft a malicious extension containing file path traversal sequences, such as ../. With this vulnerability, an attacker can write files, such as a PHP web shell, into the webroot directory.
Risk Scores
CVSS 3.1
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| OpenCart | OpenCart | 4.2.0.0 |
| OpenCart | OpenCart | 4.2.0.0, 4.2.0.0 |
Timeline
- Aug 10, 2026 CVE Published
- Aug 11, 2026 Coalition ESS Score
- Aug 12, 2026 CVE Updated
- Aug 16, 2026 Security Advisory
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score