VDB

CVE-2026-18412

CVE-2026-18412 PUBLISHED CVSS 9.1 CRITICAL

Reported by certcc · Published August 10, 2026

OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 extension installer extracts these zip files, but does not validate that the extracted paths stay inside the intended extraction directory. An attacker can craft a malicious extension containing file path traversal sequences, such as ../. With this vulnerability, an attacker can write files, such as a PHP web shell, into the webroot directory.

Risk Scores

CVSS 3.1
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
OpenCartOpenCart4.2.0.0
OpenCartOpenCart4.2.0.0, 4.2.0.0

Timeline

  • Aug 10, 2026 CVE Published
  • Aug 11, 2026 Coalition ESS Score
  • Aug 12, 2026 CVE Updated
  • Aug 16, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score
  • Aug 26, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›