LOW
OpenCart
CVE published 2026-09-02
CVE-2026-84437
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-02T02:17:20.087Z and has not been modified since then. OpenCart 4.1.0.3/4.1.0.4 is affected by a cross-site scripting vulnerability in the Autocomplete Workflow of the catalog/controller/account/address.php file. The manipulation of the address_1 argument leads to cross-site scripting. The attack ca [truncated]