CVE-2025-45892
Last modified
CVE-2025-45892 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via the blog editor. The vulnerability arises because input in the blog's editor is not properly sanitized or escaped before being rendered. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via the blog editor. The vulnerability arises because input in the blog's editor is not properly sanitized or escaped before being rendered. This allows attackers to inject malicious JavaScript code
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opencart | Opencart | <= 4.1.0.4 |
References
- https://packetstorm.news/files/id/202886Third Party Advisory
- https://www.opencart.comProduct
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-45892?
How severe is CVE-2025-45892?
How do I fix CVE-2025-45892?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-4588The 360 Photo Spheres plugin for WordPress is vulnerable to …6.4
- CVE-2025-45880A cross-site scripting (XSS) vulnerability in the data resou…6.1
- CVE-2025-45885PHPGURUKUL Vehicle Parking Management System v1.13 is vulner…9.8
- CVE-2025-45887Yifang CMS v2.0.2 is vulnerable to Server-Side Request Forge…9.1
- CVE-2025-4589The Bon Toolkit plugin for WordPress is vulnerable to Stored…6.4
- CVE-2025-45890Directory Traversal vulnerability in novel plus before v.5.1…9.8
- CVE-2025-45893OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Sit…6.1
- CVE-2025-4590The Daisycon prijsvergelijkers plugin for WordPress is vulne…6.4
- CVE-2025-4591The Weluka Lite plugin for WordPress is vulnerable to Stored…6.4
- CVE-2025-4592The AI Image Lab – Free AI Image Generator plugin for WordPr…4.3
- CVE-2025-4593The WP Register Profile With Shortcode plugin for WordPress …6.5
- CVE-2025-45931An issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D882…9.8
Are you affected by CVE-2025-45892?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
