CVE-2026-54644Medium· 6.1▾ TwilightPoC availableCubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and on…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 33.6 · likelihood 0.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.1%
Exploit-DB (last check)
CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54645Medium· 4.8CubeCart is an ecommerce software solution
CVE-2026-54646High· 7.2CubeCart is an ecommerce software solution
CVE-2026-54647High· 7.2CubeCart is an ecommerce software solution
CVE-2026-54648Medium· 6.5CubeCart is an ecommerce software solution
CVE-2026-54643Medium· 5.4CubeCart is an ecommerce software solution
CVE-2026-54642Medium· 5.3CubeCart is an ecommerce software solution