📦 Cubecart

by Cubecart

🔍 What is Cubecart?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-34832

CRITICAL CVSS 9.8 Jun 6, 2024

This CVE describes a directory traversal vulnerability in CubeCart that allows attackers to upload malicious files to arbitrary locations on the server. Attackers can exploit this via crafted _g and n...

CVE-2025-59335

HIGH CVSS 7.1 Sep 22, 2025

CubeCart ecommerce software versions before 6.5.11 fail to automatically expire user sessions after password changes. This allows attackers who have compromised an account to maintain access even afte...

CVE-2024-33438

HIGH CVSS 8.0 Apr 29, 2024

This CVE describes a file upload vulnerability in CubeCart e-commerce software that allows authenticated users to upload malicious .phar files, leading to arbitrary code execution. It affects CubeCart...

CVE-2023-38130

HIGH CVSS 8.1 Nov 17, 2023

A cross-site request forgery (CSRF) vulnerability in CubeCart e-commerce software allows unauthenticated remote attackers to delete data from the system. This affects all CubeCart installations prior ...

CVE-2023-47675

HIGH CVSS 7.2 Nov 17, 2023

CVE-2023-47675 is an OS command injection vulnerability in CubeCart e-commerce software that allows authenticated administrators to execute arbitrary commands on the underlying operating system. This ...

CVE-2025-59413

MEDIUM CVSS 6.5 Sep 22, 2025

CubeCart versions before 6.5.11 contain a logic flaw in the newsletter subscription endpoint that allows attackers to unsubscribe any user without consent. By manipulating the force_unsubscribe parame...

CVE-2025-59412

MEDIUM CVSS 5.4 Sep 22, 2025

CubeCart versions before 6.5.11 have a cross-site scripting (XSS) vulnerability in the product reviews feature. Attackers can inject malicious HTML into review descriptions, which gets executed when a...