Zen-cart

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 28
    Known Exploited: 0
    2
    Critical Level Threats
    6
    High Level Threats
    18
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-9103

    ZenCart CKEditor cross site scripting

    Last Modified: Apr 15, 2026
    Published: Aug 18, 2025

    CVE-2024-5762

    Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability

    Last Modified: Aug 23, 2024
    Published: Aug 21, 2024

    CVE-2020-6578

    Zen Cart 1.5.6d allows reflected XSS via the main_page parameter to includes/templates/template_default/common/tpl_main_page.php or includes/templates/responsive_classic/common/tpl_main_page.php.

    Last Modified: Nov 21, 2024
    Published: Mar 19, 2021

    CVE-2021-3291

    Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command.

    Last Modified: Nov 21, 2024
    Published: Jan 26, 2021

    CVE-2015-8352

    Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act parameter to ajax.php.

    Last Modified: Apr 20, 2025
    Published: Aug 24, 2017
    Items Per Page
    Zen-Cart Vulnerabilities & Security CVEs | CVE-DB