Vulnerabilidades en cubecart

20 resultados
Análisis Vexday

CubeCart apresenta 13 vulnerabilidades catalogadas, com 9 publicações nos últimos 90 dias indicando atividade contínua de descoberta de falhas. A fraqueza dominante é Cross-Site Scripting (CWE-79), típica em plataformas de e-commerce, embora nenhuma esteja sob exploração ativa no momento. Com 3 vulnerabilidades críticas, o risco requer atenção em curto prazo para ambientes em produção.

CVE-2026-54647HIGHCubeCart : SQL Injection via download_expire Parameter in settings.index.inc.phpEPSS 1.9%CVE-2026-54646HIGHCubeCart: SQL Identifier Injection via Backtick Bypass in maintenance.index.inc.phpEPSS 1.9%CVE-2026-54645MEDIUMCubeCart: Stored XSS in Product Description Editor via Global Sanitizer BypassEPSS 1.1%CVE-2026-44377CRITICALCubeCart: Server-Side Template Injection (SSTI) in Smarty Templates leading to RCEEPSS 1.0%CVE-2026-54644MEDIUMCubeCart: XSS via Anchor Tag Attribute Injection in gui.class.php Message SystemEPSS 0.9%CVE-2026-45053CRITICALCubeCart: Authenticated Arbitrary File Upload to RCE in REST Files APIEPSS 0.8%CVE-2026-44376MEDIUMCubeCart: Reflected XSS in Store Search BarEPSS 0.7%CVE-2026-54648MEDIUMCubeCart: Missing Authorization Check in customers.gdpr.inc.php Leads to Unauthorized Customer Data DeletionEPSS 0.6%CVE-2026-45708HIGHCubeCart: Authenticated RCE via Invoice Template → Order PrintEPSS 0.5%CVE-2026-45714CRITICALCubeCart: Server-Side Template Injection (SSTI) in Smarty Templates leading to RCEEPSS 0.5%CVE-2026-39358HIGHCubeCart: Time-based Blind SQL InjectionEPSS 0.4%CVE-2026-45054MEDIUMCubeCart: Authenticated SQL Injection via `sort[]` Parameter in Admin Orders Transactions ListingEPSS 0.4%CVE-2025-59413MEDIUMCubeCart Unauthorized Newsletter Unsubscription via force_unsubscribe ParameterEPSS 0.4%CVE-2026-54643MEDIUMCubeCart: Missing Authorization Check for Order Note Deletion in orders.index.inc.phpEPSS 0.4%CVE-2026-54642MEDIUMCubeCart: CSRF Protection Missing for Download Resets and Card Deletions in orders.index.inc.phpEPSS 0.3%CVE-2025-59411MEDIUMCubeCart Stored/Reflected HTML Injection Vulnerability in Contact EnquiryEPSS 0.3%CVE-2025-59412MEDIUMCubeCart Vulnerable to HTML Injection in Product Reviews Allows Malicious Links and DefacementEPSS 0.3%CVE-2026-39428MEDIUMCubeCart: Stored Cross-Site Scripting (XSS)EPSS 0.2%CVE-2025-59335HIGHCubeCart Session Not Invalidated After Password ChangeEPSS 0.2%CVE-2026-45055HIGHCubeCart: Pre-Authenticated Password Reset Link Poisoning via HTTP Host HeaderEPSS 0.2%