Vulnerabilities
19 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-21719 | An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to execute an arbitrary OS comm An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to execute an arbitrary OS command. NVD description · AI analysis pending | 8.6 group max | 1% |
| — | ||
| CVE-2025-59335 | CubeCart is an ecommerce software solution. CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration following a user's password change. This oversight poses a security risk, as if a user forgets to log out from a location where they accessed their account, an unauthorized user can maintain access even after the password has been changed. Due to this bug, if an account has already been compromised, the legitimate user has no way to revoke the attacker’s access. The malicious actor retains full access to the account until their session naturally expires. This means the account remains insecure even after the password has been changed. This issue has been patched in version 6.5.11. NVD description · AI analysis pending | 7.1 group max | <1% | PoC |
| — | |
| CVE-2024-34832 | Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node par Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node parameters. NVD description · AI analysis pending | 9.8 | 5% | PoC |
| — | |
| CVE-2024-33438 | File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file. File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file. NVD description · AI analysis pending | 8.0 | 1% | PoC |
| — | |
| CVE-2023-38130 | Cross-site request forgery (CSRF) vulnerability in CubeCart prior to 6.5.3 allows a remote unauthenticated attacker to delete data in the system. Cross-site request forgery (CSRF) vulnerability in CubeCart prior to 6.5.3 allows a remote unauthenticated attacker to delete data in the system. NVD description · AI analysis pending | 8.1 group max | <1% |
| — | ||
| CVE-2021-33394 | Cubecart 6.4.2 allows Session Fixation. Cubecart 6.4.2 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able to create a new session cookie value and inject it to a victim. After the victim logs in, the injected cookie becomes valid, giving the attacker access to the user's account through the active session. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2018-20716 | CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature. CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2018-20703 | CubeCart 6.2.2 has Reflected XSS via a /{ADMIN-FILE}/ query string. CubeCart 6.2.2 has Reflected XSS via a /{ADMIN-FILE}/ query string. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2017-2098 | Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors. Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors. NVD description · AI analysis pending | 6.5 group max | 2% |
| — |