CubeCart是CubeCart开源的一个电子商务软件。 CubeCart 6.7.3之前版本存在代码注入漏洞,该漏洞源于具有文档编辑权限的管理员可以在发票编辑器中保存原始PHP代码,导致任何管理员点击打印时,渲染的模板被写入可访问的文件,允许未经身份验证的访问者获取并执行该文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45053 | 9.1 CRITICAL | CubeCart: Authenticated Arbitrary File Upload to RCE in REST Files API |
| CVE-2026-45714 | 9.1 CRITICAL | CubeCart: Server-Side Template Injection (SSTI) in Smarty Templates leading to RCE |
| CVE-2026-44377 | 9.1 CRITICAL | CubeCart: Server-Side Template Injection (SSTI) in Smarty Templates leading to RCE |
| CVE-2026-45055 | 8.1 HIGH | CubeCart: Pre-Authenticated Password Reset Link Poisoning via HTTP Host Header |
| CVE-2026-39358 | 7.2 HIGH | CubeCart: Time-based Blind SQL Injection |
| CVE-2026-44376 | 6.1 MEDIUM | CubeCart: Reflected XSS in Store Search Bar |
| CVE-2026-45054 | 4.9 MEDIUM | CubeCart: Authenticated SQL Injection via `sort[]` Parameter in Admin Orders Transactions |
| CVE-2026-39428 | 4.8 MEDIUM | CubeCart: Stored Cross-Site Scripting (XSS) |
No comments yet