CVE-2026-54642Medium· 5.3▾ SunlitCubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored-payment-card action in admin/sources/orders.index.inc.php use state-changing GET requests and are omitted from the pr…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored-payment-card action in admin/sources/orders.index.inc.php use state-changing GET requests and are omitted from the protection map in admin/skins/default/csrf.inc.php. A remote attacker can induce an authenticated administrator to issue one of these requests without a validated session token, causing unintended resets of electronic download usage counters or deletion of stored customer payment-card tokens. This issue is fixed in version 6.7.5.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54646High· 7.2CubeCart is an ecommerce software solution
CVE-2026-54647High· 7.2CubeCart is an ecommerce software solution
CVE-2026-54648Medium· 6.5CubeCart is an ecommerce software solution
CVE-2026-54643Medium· 5.4CubeCart is an ecommerce software solution
CVE-2026-54644Medium· 6.1CubeCart is an ecommerce software solution
CVE-2026-54645Medium· 4.8CubeCart is an ecommerce software solution