Vulnerability index

Browse CVEs

25 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-34018 An SQL injection vulnerability exists in CubeCart prior to 6.6.0, which may allow an attacker to execute an arbitrary SQL statement on the product. Cubecart 6.6.0+ Fix from $2,3002026-04-17 HIGH 7.2 CVE-2026-21719 An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to execute an arbitr… Cubecart 6.6.0+ Fix from $1,9502026-04-17 MEDIUM 6.5 CVE-2025-59413 CubeCart is an ecommerce software solution. Prior to version 6.5.11, a logic flaw exists in the newsletter subscription endpoint that allows an attac… Cubecart 6.5.11+ Fix from $1,6002025-09-22 HIGH 7.1 CVE-2025-59335 CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration following a user's password … Cubecart 6.5.11+ Fix from $1,9502025-09-22 MEDIUM 5.4 CVE-2025-59411 CubeCart is an ecommerce software solution. Prior to version 6.5.11, the contact form’s Enquiry field accepts raw HTML and that HTML is included verb… Cubecart 6.5.11+ Fix from $1,6002025-09-22 MEDIUM 5.4 CVE-2025-59412 CubeCart is an ecommerce software solution. Prior to version 6.5.11, a vulnerability exists in the product reviews feature where user-supplied input … Cubecart 6.5.11+ Fix from $1,6002025-09-22 CRITICAL 9.8 CVE-2024-34832EPSS 5% Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g a… Cubecart 6.5.5+ Fix from $2,3002024-06-06 HIGH 8.0 CVE-2024-33438 File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file. Cubecart 6.5.5+ Fix from $1,9502024-04-29 HIGH 8.1 CVE-2023-38130 Cross-site request forgery (CSRF) vulnerability in CubeCart prior to 6.5.3 allows a remote unauthenticated attacker to delete data in the system. Cubecart 6.5.3+ Fix from $1,9502023-11-17 HIGH 7.2 CVE-2023-47675 CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to execute an arbitrary OS command. Cubecart 6.5.3+ Fix from $1,9502023-11-17 MEDIUM 6.5 CVE-2023-42428 Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to delete direct… Cubecart 6.5.3+ Fix from $1,6002023-11-17 MEDIUM 5.4 CVE-2021-33394 Cubecart 6.4.2 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able … Cubecart Patch available Fix from $1,6002021-05-27 CRITICAL 9.8 CVE-2018-20716 CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature. Cubecart 6.1.13+ Fix from $2,3002019-01-15 MEDIUM 5.4 CVE-2018-20703 CubeCart 6.2.2 has Reflected XSS via a /{ADMIN-FILE}/ query string. Cubecart No fix yet Fix from $1,6002019-01-13 MEDIUM 6.5 CVE-2017-2090 Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified v… Cubecart after 6.1.3 Fix from $1,6002017-04-28 MEDIUM 6.5 CVE-2017-2098 Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified v… Cubecart after 6.1.3 Fix from $1,6002017-04-28 MEDIUM 6.8 CVE-2015-6928 classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a password reset request was made, whi… Cubecart Patch available Fix from $1,6002015-09-28 MEDIUM 6.8 CVE-2014-2341EPSS 6% Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID parameter. Cubecart after 5.2.8 Fix from $1,6002014-04-22 CRITICAL 9.8 CVE-2013-1465EPSS 7% The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objec… Cubecart after 5.2.0 Fix from $2,3002013-02-08 MEDIUM 5.8 CVE-2012-0865 Multiple open redirect vulnerabilities in CubeCart 3.0.20 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phi… Cubecart after 3.0.20 Fix from $1,6002012-02-21 HIGH 7.5 CVE-2010-4903 SQL injection vulnerability in index.php in CubeCart 4.3.3 allows remote attackers to execute arbitrary SQL commands via the searchStr parameter. Cubecart Mitigation only Fix from $1,9502011-10-08 MEDIUM 5.0 CVE-2011-3724 CubeCart 4.4.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an… Cubecart No fix yet Fix from $1,6002011-09-23 HIGH 7.5 CVE-2010-1931 SQL injection vulnerability in includes/content/cart.inc.php in CubeCart PHP Shopping cart 4.3.4 through 4.3.9 allows remote attackers to execute arb… Cubecart Patch available Fix from $1,9502010-06-10 HIGH 7.5 CVE-2009-4060 SQL injection vulnerability in includes/content/viewProd.inc.php in CubeCart before 4.3.7 remote attackers to execute arbitrary SQL commands via the … Cubecart after 4.3.6 Fix from $1,9502009-11-24 HIGH 7.5 CVE-2009-3904EPSS 9% classes/session/cc_admin_session.php in CubeCart 4.3.4 does not properly restrict administrative access permissions, which allows remote attackers to… Cubecart Patch available Fix from $1,9502009-11-06