PatchSiren

OpenCart CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW OpenCart CVE published 2026-09-02

CVE-2026-84437

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-02T02:17:20.087Z and has not been modified since then. OpenCart 4.1.0.3/4.1.0.4 is affected by a cross-site scripting vulnerability in the Autocomplete Workflow of the catalog/controller/account/address.php file. The manipulation of the address_1 argument leads to cross-site scripting. The attack ca [truncated]