Zetlyn

CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5.

cve CVE-2026-54644 2 sources, 2 claims · Watch

NVD writes:
CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5. the claim

What it is to other things

In words only, so not counted until a person confirms one:

affectscubecart/v6
NVD says “cubecart · v6”
made_bycubecart
NVD says “cubecart”

What each source says

PropertySourceSaidMeans here
Author
author
Exploit-DBMikail KOCADAĞ
receipt
Source
Exploit-DB
Its words
Mikail KOCADAĞ
Read by
field:author
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Mikail KOCADAĞ",
  "codes": "CVE-2026-54644",
  "date_added": "2026-08-31",
  "date_published": "2026-08-31",
  "date_updated": "2026-08-31",
  "description": "CubeCart 6.7.4 - Cross-Site Scripting",
  "file": "exploits/multiple/webapps/52661.txt",
  "id": "52661",
  "platform": "multiple",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "webapps",
  "verified": "0"
}
—
Cvss
cvss
NVD6.1
receipt
Source
NVD
Its words
6.1
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "v6",
            "vendor": "cubecart",
            "versions": [
              {
                "status": "affected",
                "version": "< 6.7.5"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5."
      }
    ],
    "id": "CVE-2026-54644",
    "lastModified": "2026-09-23T18:12:04.247",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.7,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-54644",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T20:02:00.554438Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-17T22:17:02.283",
    "references": [
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/blob/6.7.5/admin/sources/release_notes/6.7.5.inc.php"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/commit/7c4c0081fd346578a95738f480ef647116ee1c82"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/releases/tag/6.7.5"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Awaiting Analysis",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Platform
platform
Exploit-DBmultiple
receipt
Source
Exploit-DB
Its words
multiple
Read by
field:platform
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Mikail KOCADAĞ",
  "codes": "CVE-2026-54644",
  "date_added": "2026-08-31",
  "date_published": "2026-08-31",
  "date_updated": "2026-08-31",
  "description": "CubeCart 6.7.4 - Cross-Site Scripting",
  "file": "exploits/multiple/webapps/52661.txt",
  "id": "52661",
  "platform": "multiple",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "webapps",
  "verified": "0"
}
—
Product
product
NVDv6
receipt
Source
NVD
Its words
v6
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
2026-09-29 17:49 UTCv6
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "v6",
            "vendor": "cubecart",
            "versions": [
              {
                "status": "affected",
                "version": "< 6.7.5"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5."
      }
    ],
    "id": "CVE-2026-54644",
    "lastModified": "2026-09-23T18:12:04.247",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.7,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-54644",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T20:02:00.554438Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-17T22:17:02.283",
    "references": [
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/blob/6.7.5/admin/sources/release_notes/6.7.5.inc.php"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/commit/7c4c0081fd346578a95738f480ef647116ee1c82"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/releases/tag/6.7.5"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Awaiting Analysis",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Status
status
NVDAwaiting Analysis
receipt
Source
NVD
Its words
Awaiting Analysis
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "v6",
            "vendor": "cubecart",
            "versions": [
              {
                "status": "affected",
                "version": "< 6.7.5"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5."
      }
    ],
    "id": "CVE-2026-54644",
    "lastModified": "2026-09-23T18:12:04.247",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.7,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-54644",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T20:02:00.554438Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-17T22:17:02.283",
    "references": [
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/blob/6.7.5/admin/sources/release_notes/6.7.5.inc.php"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/commit/7c4c0081fd346578a95738f480ef647116ee1c82"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/releases/tag/6.7.5"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Awaiting Analysis",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Type
type
Exploit-DBwebapps
receipt
Source
Exploit-DB
Its words
webapps
Read by
field:type
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Mikail KOCADAĞ",
  "codes": "CVE-2026-54644",
  "date_added": "2026-08-31",
  "date_published": "2026-08-31",
  "date_updated": "2026-08-31",
  "description": "CubeCart 6.7.4 - Cross-Site Scripting",
  "file": "exploits/multiple/webapps/52661.txt",
  "id": "52661",
  "platform": "multiple",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "webapps",
  "verified": "0"
}
—
Vendor
vendor
NVDcubecart
receipt
Source
NVD
Its words
cubecart
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
2026-09-29 17:49 UTCcubecart
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "v6",
            "vendor": "cubecart",
            "versions": [
              {
                "status": "affected",
                "version": "< 6.7.5"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5."
      }
    ],
    "id": "CVE-2026-54644",
    "lastModified": "2026-09-23T18:12:04.247",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.7,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-54644",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T20:02:00.554438Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-17T22:17:02.283",
    "references": [
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/blob/6.7.5/admin/sources/release_notes/6.7.5.inc.php"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/commit/7c4c0081fd346578a95738f480ef647116ee1c82"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/releases/tag/6.7.5"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Awaiting Analysis",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Verified
verified
Exploit-DBfalse
receipt
Source
Exploit-DB
Its words
0
Read by
field:verified
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Mikail KOCADAĞ",
  "codes": "CVE-2026-54644",
  "date_added": "2026-08-31",
  "date_published": "2026-08-31",
  "date_updated": "2026-08-31",
  "description": "CubeCart 6.7.4 - Cross-Site Scripting",
  "file": "exploits/multiple/webapps/52661.txt",
  "id": "52661",
  "platform": "multiple",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "webapps",
  "verified": "0"
}
—

vulnerability

CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5.
zetlyn/cve-nvd · 2026-09-17
cvss 6.1 product v6 status Awaiting Analysis vendor cubecart source

exploit

CubeCart 6.7.4 - Cross-Site Scripting
zetlyn/cve-exploitdb · 2026-08-31
author Mikail KOCADAĞ platform multiple type webapps verified false source