Cubecart is a self-hosted e-commerce platform with a concentrated vulnerability footprint centered on its single core product. Vulnerabilities affecting this vendor skew toward serious outcomes, frequently acquire public exploit code, and recur through a durable set of web-application weaknesses: path traversal, SQL injection, cross-site scripting, OS command injection, and cross-site request forgery. These flaws are characteristic of the input-handling and access-control challenges inherent to e-commerce applications, where user-supplied data flows through multiple processing layers and administrative functions carry high privileges. Defenders running Cubecart instances should prioritize patching releases and implement layered input validation and network segmentation; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cubecart over time
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-1465CRITICAL The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objects via a crafted shipping param | Feb 8, 2013 | 9.8 | 37 | NO | YES |
CVE-2009-3904HIGH classes/session/cc_admin_session.php in CubeCart 4.3.4 does not properly restrict administrative access permissions, which allows remote attackers to bypass restrictions and gain a | Nov 6, 2009 | 7.5 | 33 | NO | YES |
CVE-2026-34018CRITICAL An SQL injection vulnerability exists in CubeCart prior to 6.6.0, which may allow an attacker to execute an arbitrary SQL statement on the product. | Apr 17, 2026 | 9.8 | 31 | NO | NO |
CVE-2010-1931HIGH SQL injection vulnerability in includes/content/cart.inc.php in CubeCart PHP Shopping cart 4.3.4 through 4.3.9 allows remote attackers to execute arbitrary SQL commands via the shi | Jun 10, 2010 | 7.5 | 30 | NO | YES |
CVE-2018-20716CRITICAL CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature. | Jan 15, 2019 | 9.8 | 29 | NO | NO |
CVE-2012-0865MEDIUM Multiple open redirect vulnerabilities in CubeCart 3.0.20 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the | Feb 21, 2012 | 5.8 | 29 | NO | YES |
CVE-2024-34832CRITICAL Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node parameters. | Jun 6, 2024 | 9.8 | 28 | NO | NO |
CVE-2014-2341MEDIUM Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID parameter. | Apr 22, 2014 | 6.8 | 28 | NO | YES |
CVE-2009-4060HIGH SQL injection vulnerability in includes/content/viewProd.inc.php in CubeCart before 4.3.7 remote attackers to execute arbitrary SQL commands via the productId parameter. | Nov 24, 2009 | 7.5 | 28 | NO | YES |
CVE-2026-21719HIGH An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to execute an arbitrary OS command. | Apr 17, 2026 | 7.2 | 24 | NO | NO |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cubecart.
Media articles that mention a CVE ID that affects a product developed by Cubecart — matched by CVE ID, not by vendor name.