cubecart
7 known vulnerabilities in cubecart, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-54648 CVSS 6.5 medium CubeCart is an ecommerce software solution. Prior to 6.7.5, the GDPR tools in admin/sources/customers.gdpr.inc.php rely on page-level…
- CVE-2026-54647 CVSS 7.2 high CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates the…
- CVE-2026-54646 CVSS 7.2 high CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator-controlled…
- CVE-2026-54645 CVSS 4.8 medium CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, description_short…
- CVE-2026-54644 CVSS 6.1 medium CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit…
- CVE-2026-54643 CVSS 5.4 medium CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete-note handler in admin/sources/orders.index.inc.php verifies only…
- CVE-2026-54642 CVSS 5.3 medium CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored-payment-card…