Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 11 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:opencart:opencart:4.0.2.3:*:*:*:*:*:*:* |
Sun, 08 Mar 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in OpenCart 4.0.2.3. Affected by this issue is the function Save of the file admin/controller/design/template.php of the component Incomplete Fix CVE-2024-36694. Such manipulation leads to improper neutralization of special elements used in a template engine. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | OpenCart Incomplete Fix CVE-2024-36694 template.php save special elements used in a template engine | |
| First Time appeared |
Opencart
Opencart opencart |
|
| Weaknesses | CWE-1336 CWE-791 |
|
| CPEs | cpe:2.3:a:opencart:opencart:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Opencart
Opencart opencart |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-03-11T13:44:45.059Z
Reserved: 2026-03-07T10:59:21.497Z
Link: CVE-2026-3714
Updated: 2026-03-11T13:44:36.804Z
Status : Analyzed
Published: 2026-03-08T07:16:13.293
Modified: 2026-03-09T18:37:31.480
Link: CVE-2026-3714
No data.
OpenCVE Enrichment
Updated: 2026-04-16T10:45:26Z