CVEs we hold for Cubecart
Records whose assigning authority named Cubecart as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-54648CubeCart: Missing Authorization Check in customers.gdpr.inc.php Leads to Unauthorized Customer Data Deletioncubecart v6
CVE-2026-54647CubeCart : SQL Injection via download_expire Parameter in settings.index.inc.phpcubecart v6
CVE-2026-54646CubeCart: SQL Identifier Injection via Backtick Bypass in maintenance.index.inc.phpcubecart v6
CVE-2026-54645CubeCart: Stored XSS in Product Description Editor via Global Sanitizer Bypasscubecart v6
CVE-2026-54644CubeCart: XSS via Anchor Tag Attribute Injection in gui.class.php Message Systemcubecart v6
CVE-2026-54643CubeCart: Missing Authorization Check for Order Note Deletion in orders.index.inc.phpcubecart v6
CVE-2026-54642CubeCart: CSRF Protection Missing for Download Resets and Card Deletions in orders.index.inc.phpcubecart v6
CVE-2026-45714CubeCart: Server-Side Template Injection (SSTI) in Smarty Templates leading to RCEcubecart v6
CVE-2026-45055CubeCart: Pre-Authenticated Password Reset Link Poisoning via HTTP Host Headercubecart v6
CVE-2026-45054CubeCart: Authenticated SQL Injection via `sort[]` Parameter in Admin Orders Transactions Listingcubecart v6
CVE-2026-44377CubeCart: Server-Side Template Injection (SSTI) in Smarty Templates leading to RCEcubecart v6
CVE-2025-59413CubeCart Unauthorized Newsletter Unsubscription via force_unsubscribe Parametercubecart v6
CVE-2025-59412CubeCart Vulnerable to HTML Injection in Product Reviews Allows Malicious Links and Defacementcubecart v6
29 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.