๐Ÿ” CVE Alert

CVE-2026-54642

UNKNOWN 0.0

CubeCart: CSRF Protection Missing for Download Resets and Card Deletions in orders.index.inc.php

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored-payment-card action in admin/sources/orders.index.inc.php use state-changing GET requests and are omitted from the protection map in admin/skins/default/csrf.inc.php. A remote attacker can induce an authenticated administrator to issue one of these requests without a validated session token, causing unintended resets of electronic download usage counters or deletion of stored customer payment-card tokens. This issue is fixed in version 6.7.5.

CWE CWE-352
Vendor cubecart
Product v6
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for cubecart v6

Be the first to know when new unknown vulnerabilities affecting cubecart v6 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

cubecart / v6
< 6.7.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/cubecart/v6/security/advisories/GHSA-cq6g-rf5m-42xg github.com: https://github.com/cubecart/v6/commit/204122caa136f5be33f239d7f1ffa5775071025d github.com: https://github.com/cubecart/v6/blob/6.7.5/admin/sources/release_notes/6.7.5.inc.php github.com: https://github.com/cubecart/v6/releases/tag/6.7.5