Hi, i've got a couple of openbugbounty reports outlining an XSS issue on the search function. I'm running 3.0.2.0
Parameter: index.php?route=product/search&search=
Is this something inherent in the opencart 3.0.2.0 release and later patched, or is it possibly coming from the theme i'm using?
Parameter: index.php?route=product/search&search=
Is this something inherent in the opencart 3.0.2.0 release and later patched, or is it possibly coming from the theme i'm using?
As far as I know, OpenCart has no problems with such.
Therefore it could come from your theme if they have their own function for that.
Maybe you share the used theme here (which should always be provided when you read this: Forum Rules ).
Therefore it could come from your theme if they have their own function for that.
Maybe you share the used theme here (which should always be provided when you read this: Forum Rules ).
Full Stack Web Developer :: Dedicated OpenCart Development & Support DACH Region
Contact for Custom Work / Fast Support.
Were there any more details?
There is CVE-2025-1746 which mentions an XSS issue with product/search.
https://www.incibe.es/en/incibe-cert/no ... s-opencart
There isn't much in the way of details and It says it's fixed 4.1.0.0 and above, but no mention if it affects 3.0.x.
There is CVE-2025-1746 which mentions an XSS issue with product/search.
https://www.incibe.es/en/incibe-cert/no ... s-opencart
There isn't much in the way of details and It says it's fixed 4.1.0.0 and above, but no mention if it affects 3.0.x.
The theme is Journal 2.OSWorX wrote: ↑Tue Jul 15, 2025 12:48 amAs far as I know, OpenCart has no problems with such.
Therefore it could come from your theme if they have their own function for that.
Maybe you share the used theme here (which should always be provided when you read this: Forum Rules ).
Yes, details as below. I've omitted the site name for obvious reasonsADD Creative wrote: ↑Tue Jul 15, 2025 1:10 amWere there any more details?
There is CVE-2025-1746 which mentions an XSS issue with product/search.
https://www.incibe.es/en/incibe-cert/no ... s-opencart
There isn't much in the way of details and It says it's fixed 4.1.0.0 and above, but no mention if it affects 3.0.x.

I am certain it's resolved in OpenCart 3.0.4.0 or later. Besides, you are using the Journal2 framework, which isn't a proper standard OpenCart theme, also it uses its own search function.
Export/Import Tool * SpamBot Buster * Unused Images Manager * Instant Option Price Calculator * Number Option * Google Tag Manager * Survey Plus * OpenTwig
I wasn't able to recreate the issue on 3.0.2.0 or 3.0.4.1. That suggests the issue is with your theme or an extension you are using.
Who is online
Users browsing this forum: Amazon [Bot], Bing [Bot], Google [Bot], Majestic-12 [Bot], paola_84 and 20 guests