Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-54644— CubeCart: XSS via Anchor Tag Attribute Injection in gui.class.php Message System

Quick assessment

Affected
cubecart v6
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

CubeCart 是一款电子商务软件解决方案。在 6.7.5 版本之前, 中的 方法使用 过滤器允许在错误、信息和警告消息中保留锚点( )元素,但同时保留了不安全的 值及 事件处理程序。攻击者控制的搜索或输入数据若进入 GUI 消息,可以携带 URI 或事件处理器通过该过滤器。当受害者查看或交互渲染后的锚点时,其浏览器会话中将执行 JavaScript 代码,从而可能导致会话暴露或未经授权的应用程序操作。该问题已在 6.7.5 版本中修复。

CVSS 6.1 · Medium

Public Exploits 1

ExploitDB · 1 EDB-52661 [webapps]

Possible ATT&CK Techniques 1 AI

T1059.007 · JavaScript
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54644

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
CubeCart: XSS via Anchor Tag Attribute Injection in gui.class.php Message System
Source: CVE Program / CVE List V5
Vulnerability Description
CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
cubecart v6 < 6.7.5 -

II. Public POCs for CVE-2026-54644

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54644

登录查看更多情报信息。

Patches & Fixes for CVE-2026-54644 (1)

Other References for CVE-2026-54644 (3)

Same Patch Batch · cubecart · 2026-09-17 · 7 CVEs total

CVE-2026-54646 7.2 HIGH CubeCart: SQL Identifier Injection via Backtick Bypass in maintenance.index.inc.php
CVE-2026-54647 7.2 HIGH CubeCart : SQL Injection via download_expire Parameter in settings.index.inc.php
CVE-2026-54648 6.5 MEDIUM CubeCart: Missing Authorization Check in customers.gdpr.inc.php Leads to Unauthorized Cust
CVE-2026-54643 5.4 MEDIUM CubeCart: Missing Authorization Check for Order Note Deletion in orders.index.inc.php
CVE-2026-54642 5.3 MEDIUM CubeCart: CSRF Protection Missing for Download Resets and Card Deletions in orders.index.i
CVE-2026-54645 4.8 MEDIUM CubeCart: Stored XSS in Product Description Editor via Global Sanitizer Bypass

IV. Related Vulnerabilities

V. Comments for CVE-2026-54644

No comments yet


Leave a comment