Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2026-34018
An SQL injection vulnerability exists in CubeCart prior to 6.6.0, which may allow an attacker to execute an arbitrary SQL statement on the product.
Cubecart
6.6.0+
HIGH 7.2
CVE-2026-21719
An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to execute an arbitr…
Cubecart
6.6.0+
MEDIUM 6.5
CVE-2025-59413
CubeCart is an ecommerce software solution. Prior to version 6.5.11, a logic flaw exists in the newsletter subscription endpoint that allows an attac…
Cubecart
6.5.11+
HIGH 7.1
CVE-2025-59335
CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration following a user's password …
Cubecart
6.5.11+
MEDIUM 5.4
CVE-2025-59411
CubeCart is an ecommerce software solution. Prior to version 6.5.11, the contact form’s Enquiry field accepts raw HTML and that HTML is included verb…
Cubecart
6.5.11+
MEDIUM 5.4
CVE-2025-59412
CubeCart is an ecommerce software solution. Prior to version 6.5.11, a vulnerability exists in the product reviews feature where user-supplied input …
Cubecart
6.5.11+
CRITICAL 9.8
CVE-2024-34832EPSS 5%
Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g a…
Cubecart
6.5.5+
HIGH 8.0
CVE-2024-33438
File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file.
Cubecart
6.5.5+
HIGH 8.1
CVE-2023-38130
Cross-site request forgery (CSRF) vulnerability in CubeCart prior to 6.5.3 allows a remote unauthenticated attacker to delete data in the system.
Cubecart
6.5.3+
HIGH 7.2
CVE-2023-47675
CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to execute an arbitrary OS command.
Cubecart
6.5.3+
MEDIUM 6.5
CVE-2023-42428
Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to delete direct…
Cubecart
6.5.3+
MEDIUM 5.4
CVE-2021-33394
Cubecart 6.4.2 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able …
Cubecart
Patch available
CRITICAL 9.8
CVE-2018-20716
CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature.
Cubecart
6.1.13+
MEDIUM 5.4
CVE-2018-20703
CubeCart 6.2.2 has Reflected XSS via a /{ADMIN-FILE}/ query string.
Cubecart
No fix yet
MEDIUM 6.5
CVE-2017-2090
Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified v…
Cubecart
after 6.1.3
MEDIUM 6.5
CVE-2017-2098
Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified v…
Cubecart
after 6.1.3
MEDIUM 6.8
CVE-2015-6928
classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a password reset request was made, whi…
Cubecart
Patch available
MEDIUM 6.8
CVE-2014-2341EPSS 6%
Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
Cubecart
after 5.2.8
CRITICAL 9.8
CVE-2013-1465EPSS 7%
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objec…
Cubecart
after 5.2.0
MEDIUM 5.8
CVE-2012-0865
Multiple open redirect vulnerabilities in CubeCart 3.0.20 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phi…
Cubecart
after 3.0.20
HIGH 7.5
CVE-2010-4903
SQL injection vulnerability in index.php in CubeCart 4.3.3 allows remote attackers to execute arbitrary SQL commands via the searchStr parameter.
Cubecart
Mitigation only
MEDIUM 5.0
CVE-2011-3724
CubeCart 4.4.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an…
Cubecart
No fix yet
HIGH 7.5
CVE-2010-1931
SQL injection vulnerability in includes/content/cart.inc.php in CubeCart PHP Shopping cart 4.3.4 through 4.3.9 allows remote attackers to execute arb…
Cubecart
Patch available
HIGH 7.5
CVE-2009-4060
SQL injection vulnerability in includes/content/viewProd.inc.php in CubeCart before 4.3.7 remote attackers to execute arbitrary SQL commands via the …
Cubecart
after 4.3.6
HIGH 7.5
CVE-2009-3904EPSS 9%
classes/session/cc_admin_session.php in CubeCart 4.3.4 does not properly restrict administrative access permissions, which allows remote attackers to…
Cubecart
Patch available