VulnSea

cubecart has 7 CVEs on record. Disclosure cadence is accelerating: 7 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 7. The median CVSS is 6.1 (medium). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.1
Publish → KEV
Last 90 days
7 prev 0

Products

  • v6 7
7
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

cubecart vulnerabilities

CVEs affecting cubecart, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2026-54648Medium· 6.5PoC
5d ago

CubeCart is an ecommerce software solution

CubeCart is an ecommerce software solution. Prior to 6.7.5, the GDPR tools in admin/sources/customers.gdpr.inc.php rely on page-level CC_PERM_READ access and do not require CC_PERM_DELETE for the purge, no_order_purge, or delete_guests c…

Twilightcubecart · v6EPSS 0.32%via NVD
CVE-2026-54647High· 7.2PoC
5d ago

CubeCart is an ecommerce software solution

CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates the administrator-controlled download_expire POST parameter into a raw UPDATE statement for CubeCart_downloads without…

Midnightcubecart · v6EPSS 1.4%via NVD
CVE-2026-54646High· 7.2PoC
5d ago

CubeCart is an ecommerce software solution

CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator-controlled tablename values into ALTER TABLE, CHECK TABLE, and ANALYZE TABLE statements without validating the ident…

Midnightcubecart · v6EPSS 1.4%via NVD
CVE-2026-54645Medium· 4.8PoC
5d ago

CubeCart is an ecommerce software solution

CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, description_short, and spec_copy rich-text fields from $GLOBALS['RAW']['POST'] and removes only script elements befor…

Twilightcubecart · v6EPSS 1.3%via NVD
CVE-2026-54644Medium· 6.1PoC
5d ago

CubeCart is an ecommerce software solution

CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and on…

Twilightcubecart · v6EPSS 1.1%via NVD
CVE-2026-54643Medium· 5.4PoC
5d ago

CubeCart is an ecommerce software solution

CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete-note handler in admin/sources/orders.index.inc.php verifies only the presence of order_id and delete-note parameters before deleting records from CubeCart_order_notes…

Twilightcubecart · v6EPSS 0.22%via NVD
CVE-2026-54642Medium· 5.3
5d ago

CubeCart is an ecommerce software solution

CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored-payment-card action in admin/sources/orders.index.inc.php use state-changing GET requests and are omitted from the pr…

Sunlitcubecart · v6EPSS 0.22%via NVD
cubecart vulnerabilities (CVEs) · VulnSea