Vulnerability index

Browse CVEs

25 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cubecart CRITICAL 9.8
CVE-2026-34018

An SQL injection vulnerability exists in CubeCart prior to 6.6.0, which may allow an attacker to execute an arbitrary SQL statement on the product.

Fix: 6.6.0+
Fix from $2,300 2026-04-17
Cubecart HIGH 7.2
CVE-2026-21719

An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to execute an arbitr…

Fix: 6.6.0+
Fix from $1,950 2026-04-17
Cubecart MEDIUM 6.5
CVE-2025-59413

CubeCart is an ecommerce software solution. Prior to version 6.5.11, a logic flaw exists in the newsletter subscription endpoint that allows an attac…

Fix: 6.5.11+
Fix from $1,600 2025-09-22
Cubecart HIGH 7.1
CVE-2025-59335

CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration following a user's password …

Fix: 6.5.11+
Fix from $1,950 2025-09-22
Cubecart MEDIUM 5.4
CVE-2025-59411

CubeCart is an ecommerce software solution. Prior to version 6.5.11, the contact form’s Enquiry field accepts raw HTML and that HTML is included verb…

Fix: 6.5.11+
Fix from $1,600 2025-09-22
Cubecart MEDIUM 5.4
CVE-2025-59412

CubeCart is an ecommerce software solution. Prior to version 6.5.11, a vulnerability exists in the product reviews feature where user-supplied input …

Fix: 6.5.11+
Fix from $1,600 2025-09-22
Cubecart CRITICAL 9.8
CVE-2024-34832EPSS 5%

Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g a…

Fix: 6.5.5+
Fix from $2,300 2024-06-06
Cubecart HIGH 8.0
CVE-2024-33438

File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file.

Fix: 6.5.5+
Fix from $1,950 2024-04-29
Cubecart HIGH 8.1
CVE-2023-38130

Cross-site request forgery (CSRF) vulnerability in CubeCart prior to 6.5.3 allows a remote unauthenticated attacker to delete data in the system.

Fix: 6.5.3+
Fix from $1,950 2023-11-17
Cubecart HIGH 7.2
CVE-2023-47675

CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to execute an arbitrary OS command.

Fix: 6.5.3+
Fix from $1,950 2023-11-17
Cubecart MEDIUM 6.5
CVE-2023-42428

Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to delete direct…

Fix: 6.5.3+
Fix from $1,600 2023-11-17
Cubecart MEDIUM 5.4
CVE-2021-33394

Cubecart 6.4.2 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able …

Patch available
Fix from $1,600 2021-05-27
Cubecart CRITICAL 9.8
CVE-2018-20716

CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature.

Fix: 6.1.13+
Fix from $2,300 2019-01-15
Cubecart MEDIUM 5.4
CVE-2018-20703

CubeCart 6.2.2 has Reflected XSS via a /{ADMIN-FILE}/ query string.

No fix yet
Fix from $1,600 2019-01-13
Cubecart MEDIUM 6.5
CVE-2017-2090

Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified v…

Fix: after 6.1.3
Fix from $1,600 2017-04-28
Cubecart MEDIUM 6.5
CVE-2017-2098

Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified v…

Fix: after 6.1.3
Fix from $1,600 2017-04-28
Cubecart MEDIUM 6.8
CVE-2015-6928

classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a password reset request was made, whi…

Patch available
Fix from $1,600 2015-09-28
Cubecart MEDIUM 6.8
CVE-2014-2341EPSS 6%

Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID parameter.

Fix: after 5.2.8
Fix from $1,600 2014-04-22
Cubecart CRITICAL 9.8
CVE-2013-1465EPSS 7%

The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objec…

Fix: after 5.2.0
Fix from $2,300 2013-02-08
Cubecart MEDIUM 5.8
CVE-2012-0865

Multiple open redirect vulnerabilities in CubeCart 3.0.20 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phi…

Fix: after 3.0.20
Fix from $1,600 2012-02-21
Cubecart HIGH 7.5
CVE-2010-4903

SQL injection vulnerability in index.php in CubeCart 4.3.3 allows remote attackers to execute arbitrary SQL commands via the searchStr parameter.

Mitigation only
Fix from $1,950 2011-10-08
Cubecart MEDIUM 5.0
CVE-2011-3724

CubeCart 4.4.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an…

No fix yet
Fix from $1,600 2011-09-23
Cubecart HIGH 7.5
CVE-2010-1931

SQL injection vulnerability in includes/content/cart.inc.php in CubeCart PHP Shopping cart 4.3.4 through 4.3.9 allows remote attackers to execute arb…

Patch available
Fix from $1,950 2010-06-10
Cubecart HIGH 7.5
CVE-2009-4060

SQL injection vulnerability in includes/content/viewProd.inc.php in CubeCart before 4.3.7 remote attackers to execute arbitrary SQL commands via the …

Fix: after 4.3.6
Fix from $1,950 2009-11-24
Cubecart HIGH 7.5
CVE-2009-3904EPSS 9%

classes/session/cc_admin_session.php in CubeCart 4.3.4 does not properly restrict administrative access permissions, which allows remote attackers to…

Patch available
Fix from $1,950 2009-11-06