Security Cart Engine 3.0 XSS / Open Redirect / SQL Injection September 16, 2014 007admin Leave a comment Cart Engine version 3.0 suffers from cross site scripting, open redirection, and remote SQL injection vulnerabilities.