Known Vulnerabilities for CubeCart by CubeCart Limited
Listed below are 10 of the newest known vulnerabilities associated with "CubeCart" by "CubeCart Limited".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-45714 json | CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerabil... | Not Provided | 2026-05-13 | 2026-05-13 |
| CVE-2026-45708 json | CubeCart is an ecommerce software solution. Prior to 6.7.3, an admin with documents edit permission can save raw ... | Not Provided | 2026-05-13 | 2026-05-13 |
| CVE-2026-45055 json | CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the Ho... | Not Provided | 2026-05-13 | 2026-05-13 |
| CVE-2026-45054 json | CubeCart is an ecommerce software solution. Prior to 6.7.0, the admin orders-transactions listing page (admin.php?_g=orders&n... | Not Provided | 2026-05-13 | 2026-05-13 |
| CVE-2026-45053 json | CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists in th... | Not Provided | 2026-05-13 | 2026-05-13 |
| CVE-2026-44377 json | CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerabil... | Not Provided | 2026-05-13 | 2026-05-13 |
| CVE-2026-44376 json | CubeCart is an ecommerce software solution. Prior to 6.7.0, an unauthenticated Reflected XSS vulnerability exists in the Cube... | Not Provided | 2026-05-13 | 2026-05-13 |
| CVE-2026-39428 json | CubeCart is an ecommerce software solution. Prior to 6.6.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in CubeC... | Not Provided | 2026-05-13 | 2026-05-13 |
| CVE-2026-39358 json | CubeCart is an ecommerce software solution. Prior to 6.6.0, Authenticated Time-Based Blind SQL Injection vulnerabilities were... | Not Provided | 2026-05-13 | 2026-05-13 |
| CVE-2026-35496 json | A path traversal vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to ... | Not Provided | 2026-04-17 | 2026-04-17 |