CVE-2026-18412 | OpenCart 4.2.0.0 Extension Installer path traversal
A vulnerability marked as critical has been reported in OpenCart 4.2.0.0. The affected element is an unknown function of the component Extension Installer. Performing a manipulation results in path traversal.
This vulnerability is reported as CVE-2026-18412. The attack is possible to be carried out remotely. No exploit exists.