CVE-2026-54647High· 7.2▾ MidnightPoC availableCubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates the administrator-controlled download_expire POST parameter into a raw UPDATE statement for CubeCart_downloads without…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 39.6 · likelihood 0.3 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
1.4%
Last analysed / modified upstream
Exploit-DB (last check)
CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates the administrator-controlled download_expire POST parameter into a raw UPDATE statement for CubeCart_downloads without numeric validation. An authenticated administrator can supply a comma-delimited value that changes the SET clause because HTML sanitization does not neutralize SQL syntax, allowing manipulation of database columns and potentially other data within the application's database privileges. This issue is fixed in version 6.7.5.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54646High· 7.2CubeCart is an ecommerce software solution
CVE-2026-54648Medium· 6.5CubeCart is an ecommerce software solution
CVE-2026-54645Medium· 4.8CubeCart is an ecommerce software solution
CVE-2026-54644Medium· 6.1CubeCart is an ecommerce software solution
CVE-2026-54643Medium· 5.4CubeCart is an ecommerce software solution
CVE-2026-54642Medium· 5.3CubeCart is an ecommerce software solution