Known Vulnerabilities for Cubecart by Devellion
Listed below are 10 of the newest known vulnerabilities associated with "Cubecart" by "Devellion".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-44376 json | CubeCart is an ecommerce software solution. Prior to 6.7.0, an unauthenticated Reflected XSS vulnerability exists in the Cube... | Not Provided | 2026-05-13 | 2026-06-01 |
| CVE-2007-2862 json | Not Provided | 2007-05-24 | 2026-04-23 | |
| CVE-2007-2550 json | Not Provided | 2007-05-09 | 2026-04-23 | |
| CVE-2006-5109 json | Not Provided | 2006-10-03 | 2026-04-23 | |
| CVE-2006-5108 json | Not Provided | 2006-10-03 | 2026-04-23 | |
| CVE-2006-5107 json | Not Provided | 2006-10-03 | 2026-04-23 | |
| CVE-2006-4527 json | includes/content/gateway.inc.php in CubeCart 3.0.12 and earlier, when magic_quotes_gpc is disabled, uses an insufficiently re... | 2.6 - LOW | 2006-09-01 | 2008-09-05 |
| CVE-2006-4526 json | SQL injection vulnerability in includes/content/viewCat.inc.php in CubeCart 3.0.12 and earlier, when register_globals is enab... | 7.5 - HIGH | 2006-09-01 | 2008-09-05 |
| CVE-2006-4525 json | Cross-site scripting (XSS) vulnerability in CubeCart 3.0.12 and earlier, when register_globals is enabled, allows remote atta... | 4.3 - MEDIUM | 2006-09-01 | 2008-09-05 |
| CVE-2006-4268 json | Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.11 and earlier allow remote attackers to inject arbitrary... | 6.8 - MEDIUM | 2006-08-21 | 2018-10-17 |