CVE-2025-45892: XSS
OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via the blog editor. The vulnerability arises because input in the blog's editor is not properly sanitized or escaped before being rendered. This allows attackers to inject malicious JavaScript code
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-45892?
CVE-2025-45892 is classified as a medium severity vulnerability due to its potential for stored XSS attacks.
How do I fix CVE-2025-45892?
To fix CVE-2025-45892, update your OpenCart installation to a version that includes the necessary sanitization measures for the blog editor.
What does CVE-2025-45892 allow an attacker to do?
CVE-2025-45892 allows attackers to inject and execute malicious JavaScript code through the blog editor.
Which versions of OpenCart are affected by CVE-2025-45892?
CVE-2025-45892 specifically affects OpenCart version 4.1.0.4.
How can I determine if my OpenCart installation is vulnerable to CVE-2025-45892?
You can determine if your OpenCart installation is vulnerable to CVE-2025-45892 by checking if you are using version 4.1.0.4 without the appropriate security updates.