๐Ÿ” CVE Alert

CVE-2026-54645

MEDIUM 4.8

CubeCart: Stored XSS in Product Description Editor via Global Sanitizer Bypass

CVSS Score
4.8
EPSS Score
0.0%
EPSS Percentile
0th

CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, description_short, and spec_copy rich-text fields from $GLOBALS['RAW']['POST'] and removes only script elements before the values are stored and rendered through Smarty templates. An administrator with product-editing rights can store event-handler attributes, SVG content, or javascript: URIs that bypass this filter, causing persistent JavaScript execution when a storefront visitor or another administrator views the product content and enabling session exposure or unauthorized browser-context actions. This issue is fixed in version 6.7.5.

CWE CWE-79
Vendor cubecart
Product v6
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for cubecart v6

Be the first to know when new medium vulnerabilities affecting cubecart v6 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

cubecart / v6
< 6.7.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/cubecart/v6/security/advisories/GHSA-43f6-gfcf-wj9c github.com: https://github.com/cubecart/v6/commit/bd2dcdcc7da55a3731fe288b54cac8bfa3d9142a github.com: https://github.com/cubecart/v6/commit/f7abe7484691a33abcbc0806fca59d605024a75c github.com: https://github.com/cubecart/v6/blob/6.7.5/admin/sources/release_notes/6.7.5.inc.php github.com: https://github.com/cubecart/v6/releases/tag/6.7.5