Ubercart is a modestly represented e-commerce platform built on Drupal that powers a focused set of online storefronts, presenting an application-layer attack surface concentrated in web-facing checkout and catalog functionality. Its vulnerability profile centers on recurring input-handling and authentication weaknesses—improper input validation, cross-site scripting, cross-site request forgery, authentication flaws, and code injection—that are characteristic of web-application frameworks handling user-supplied data and session management. Defenders should prioritize patching and input sanitization across Ubercart installations, especially those accepting payment data; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ubercart over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-7302MEDIUM Session fixation vulnerability in the Ubercart module 6.x-2.x before 6.x-2.13 and 7.x-3.x before 7.x-3.6 for Drupal, when the "Log in new customers after checkout" option is enable | Apr 29, 2014 | 6.8 | 22 | NO | NO |
CVE-2012-2301MEDIUM The Ubercart module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer product classes" permission to execute arbitrary PHP code via unspecifi | Nov 16, 2014 | 6.0 | 21 | NO | NO |
CVE-2012-5803MEDIUM The Authorize.Net module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certifica | Nov 4, 2012 | 5.8 | 19 | NO | NO |
CVE-2012-5804MEDIUM The CyberSource module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate | Nov 4, 2012 | 5.8 | 18 | NO | NO |
CVE-2012-5802MEDIUM The PayPal module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, whi | Nov 4, 2012 | 5.8 | 18 | NO | NO |
CVE-2009-4773MEDIUM Cross-site request forgery (CSRF) vulnerability in the order-management functionality in the Ubercart module 5.x before 5.x-1.9 and 6.x before 6.x-2.1 for Drupal allows remote atta | Apr 20, 2010 | 6.8 | 18 | NO | NO |
CVE-2009-4771MEDIUM The PayPal Website Payments Standard functionality in the Ubercart module 5.x before 5.x-1.9 and 6.x before 6.x-2.1 for Drupal does not properly validate orders, which allows remot | Apr 20, 2010 | 5.0 | 15 | NO | NO |
CVE-2013-0322MEDIUM Cross-site scripting (XSS) vulnerability in Views in the Ubercart module 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via the fu | Mar 27, 2013 | 4.3 | 14 | NO | NO |
CVE-2009-4772MEDIUM Unspecified vulnerability in the PayPal Website Payments Standard functionality in the Ubercart module 5.x before 5.x-1.9 and 6.x before 6.x-2.1 for Drupal, when a custom checkout | Apr 20, 2010 | 4.3 | 14 | NO | NO |
CVE-2014-9026MEDIUM The Ubercart module 7.x-3.x before 7.x-3.7 for Drupal does not properly protect the per-user order history view, which allows remote authenticated users with the "view own orders" | Nov 20, 2014 | 4.0 | 13 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ubercart.
Media articles that mention a CVE ID that affects a product developed by Ubercart — matched by CVE ID, not by vendor name.