Zen Cart Version 1.3.8a was issued in December 2007. Since the release the following Security Patches have been released. These security patches will need to be installed manually – they are not included in version 1.3.8a.
- Patch for Local File Inclusion vulnerability
http://www.zen-cart.com/forum/showthread.php?t=102802 - Patch for SQL Injection Risk
http://www.zen-cart.com/forum/showthread.php?t=108428 - Patch for Serious Admin Vulnerability
http://www.zen-cart.com/forum/showthread.php?t=130161 - Patch for PCI Scan Error Message
http://www.zen-cart.com/forum/showthread.php?t=130701 - Patch for PHP 5.3 compatibility (Optional)
http://www.zen-cart.com/forum/showthread.php?t=140960
Notifications for Security Patches released for the 1.3 series of Zen Cart are available from the Zen Cart Support Forum: http://www.zen-cart.com/forum/showthread.php?t=131115. It is highly encouraged all Zen Cart store owners subscribe to receive security announcements, as shown below, and install security patches as they are released.


