CVE-2021-47923Critical· 9.8▾ MidnightOpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting arbitrary values into the OCSESSID cookie. Attackers can set malicious OCSESSID cookie values that the server accepts a…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting arbitrary values into the OCSESSID cookie. Attackers can set malicious OCSESSID cookie values that the server accepts and maintains, enabling session takeover and unauthorized access to user accounts.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102161High· 8.8An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards client headers) can forge their source IP address and gain administrative session privileges o…
CVE-2026-105863Critical· 9.2Payload is a free and open source headless content management system
CVE-2026-39772Medium· 5.3Unauthenticated Bypass Vulnerability in Captcha by BestWebSoft <= 5.2.8 versions.
CVE-2026-97308Medium· 4.8Unauthenticated Bypass Vulnerability in Login Lockdown <= 2.17 versions.
CVE-2026-105057Medium· 5.3Unauthenticated Bypass Vulnerability in Zero Spam <= 5.7.11 versions.
CVE-2026-41558High· 7.5Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions.