: Vulnerabilities can allow hackers to steal customer payment info or personal data.
The "patch" is notorious for dropping standalone PHP shells into /catalog/view/theme/your_theme/css/ or /image/cache/ . Filenames like image.php , editor.php , or uploader.php sit innocently among legitimate files. Visiting yoursite.com/image/cache/editor.php gives the attacker a full file manager—upload, edit, download, delete—bypassing OpenCart entirely.
: "Patched" versions might have obfuscated code that tracks your sales or redirects your checkout process to a third-party site. No Updates or Support