Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cubecart

First CVE: Mar 31, 2008Active for: 18 yearsTotal CVEs: 29
44.5
VTI Score
High

Cubecart is a self-hosted e-commerce platform with a concentrated vulnerability footprint centered on its single core product. Vulnerabilities affecting this vendor skew toward serious outcomes, frequently acquire public exploit code, and recur through a durable set of web-application weaknesses: path traversal, SQL injection, cross-site scripting, OS command injection, and cross-site request forgery. These flaws are characteristic of the input-handling and access-control challenges inherent to e-commerce applications, where user-supplied data flows through multiple processing layers and administrative functions carry high privileges. Defenders running Cubecart instances should prioritize patching releases and implement layered input validation and network segmentation; current severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
29
Total CVEs
More Total CVEs than 97% of tracked vendors
1.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cubecart over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 31, 2008
18 years ago
Most Recent CVE
Apr 17, 2026
98 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-1465CRITICAL
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objects via a crafted shipping param
Feb 8, 20139.837NOYES
CVE-2009-3904HIGH
classes/session/cc_admin_session.php in CubeCart 4.3.4 does not properly restrict administrative access permissions, which allows remote attackers to bypass restrictions and gain a
Nov 6, 20097.533NOYES
CVE-2026-34018CRITICAL
An SQL injection vulnerability exists in CubeCart prior to 6.6.0, which may allow an attacker to execute an arbitrary SQL statement on the product.
Apr 17, 20269.831NONO
CVE-2010-1931HIGH
SQL injection vulnerability in includes/content/cart.inc.php in CubeCart PHP Shopping cart 4.3.4 through 4.3.9 allows remote attackers to execute arbitrary SQL commands via the shi
Jun 10, 20107.530NOYES
CVE-2018-20716CRITICAL
CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature.
Jan 15, 20199.829NONO
CVE-2012-0865MEDIUM
Multiple open redirect vulnerabilities in CubeCart 3.0.20 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the
Feb 21, 20125.829NOYES
CVE-2024-34832CRITICAL
Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node parameters.
Jun 6, 20249.828NONO
CVE-2014-2341MEDIUM
Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
Apr 22, 20146.828NOYES
CVE-2009-4060HIGH
SQL injection vulnerability in includes/content/viewProd.inc.php in CubeCart before 4.3.7 remote attackers to execute arbitrary SQL commands via the productId parameter.
Nov 24, 20097.528NOYES
CVE-2026-21719HIGH
An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to execute an arbitrary OS command.
Apr 17, 20267.224NONO
View all 29 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products29 CVEs
52%
31%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (3.4%)
Network19 (65.5%)
Unknown9 (31.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (69.0%)
High0 (0.0%)
Unknown9 (31.0%)
User Interaction
None15 (51.7%)
Unknown9 (31.0%)
Required5 (17.2%)
Privileges Required
Low7 (24.1%)
High6 (20.7%)
None7 (24.1%)
Unknown9 (31.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
20.7% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cubecart.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cubecart — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cubecart's Products

View all 4 CNAs →

Top CWEs