CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5.
cve CVE-2026-54644 2 sources, 2 claims · Watch
NVD writes:
CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5. the claim
CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5. the claim
What it is to other things
In words only, so not counted until a person confirms one:
| affects | cubecart/v6NVD says “cubecart · v6” |
| made_by | cubecartNVD says “cubecart” |
What each source says
| Property | Source | Said | Means here | ||||
|---|---|---|---|---|---|---|---|
| Author author | Exploit-DB | Mikail KOCADAĞreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Mikail KOCADAĞ",
"codes": "CVE-2026-54644",
"date_added": "2026-08-31",
"date_published": "2026-08-31",
"date_updated": "2026-08-31",
"description": "CubeCart 6.7.4 - Cross-Site Scripting",
"file": "exploits/multiple/webapps/52661.txt",
"id": "52661",
"platform": "multiple",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "webapps",
"verified": "0"
} | — | ||||
| Cvss cvss | NVD | 6.1receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "v6",
"vendor": "cubecart",
"versions": [
{
"status": "affected",
"version": "< 6.7.5"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5."
}
],
"id": "CVE-2026-54644",
"lastModified": "2026-09-23T18:12:04.247",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 2.7,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-54644",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T20:02:00.554438Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-17T22:17:02.283",
"references": [
{
"source": "security-advisories@github.com",
"url": "https://github.com/cubecart/v6/blob/6.7.5/admin/sources/release_notes/6.7.5.inc.php"
},
{
"source": "security-advisories@github.com",
"url": "https://github.com/cubecart/v6/commit/7c4c0081fd346578a95738f480ef647116ee1c82"
},
{
"source": "security-advisories@github.com",
"url": "https://github.com/cubecart/v6/releases/tag/6.7.5"
},
{
"source": "security-advisories@github.com",
"url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-79"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Platform platform | Exploit-DB | multiplereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Mikail KOCADAĞ",
"codes": "CVE-2026-54644",
"date_added": "2026-08-31",
"date_published": "2026-08-31",
"date_updated": "2026-08-31",
"description": "CubeCart 6.7.4 - Cross-Site Scripting",
"file": "exploits/multiple/webapps/52661.txt",
"id": "52661",
"platform": "multiple",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "webapps",
"verified": "0"
} | — | ||||
| Product product | NVD | v6receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "v6",
"vendor": "cubecart",
"versions": [
{
"status": "affected",
"version": "< 6.7.5"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5."
}
],
"id": "CVE-2026-54644",
"lastModified": "2026-09-23T18:12:04.247",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 2.7,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-54644",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T20:02:00.554438Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-17T22:17:02.283",
"references": [
{
"source": "security-advisories@github.com",
"url": "https://github.com/cubecart/v6/blob/6.7.5/admin/sources/release_notes/6.7.5.inc.php"
},
{
"source": "security-advisories@github.com",
"url": "https://github.com/cubecart/v6/commit/7c4c0081fd346578a95738f480ef647116ee1c82"
},
{
"source": "security-advisories@github.com",
"url": "https://github.com/cubecart/v6/releases/tag/6.7.5"
},
{
"source": "security-advisories@github.com",
"url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-79"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Status status | NVD | Awaiting Analysisreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "v6",
"vendor": "cubecart",
"versions": [
{
"status": "affected",
"version": "< 6.7.5"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5."
}
],
"id": "CVE-2026-54644",
"lastModified": "2026-09-23T18:12:04.247",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 2.7,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-54644",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T20:02:00.554438Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-17T22:17:02.283",
"references": [
{
"source": "security-advisories@github.com",
"url": "https://github.com/cubecart/v6/blob/6.7.5/admin/sources/release_notes/6.7.5.inc.php"
},
{
"source": "security-advisories@github.com",
"url": "https://github.com/cubecart/v6/commit/7c4c0081fd346578a95738f480ef647116ee1c82"
},
{
"source": "security-advisories@github.com",
"url": "https://github.com/cubecart/v6/releases/tag/6.7.5"
},
{
"source": "security-advisories@github.com",
"url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-79"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Type type | Exploit-DB | webappsreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Mikail KOCADAĞ",
"codes": "CVE-2026-54644",
"date_added": "2026-08-31",
"date_published": "2026-08-31",
"date_updated": "2026-08-31",
"description": "CubeCart 6.7.4 - Cross-Site Scripting",
"file": "exploits/multiple/webapps/52661.txt",
"id": "52661",
"platform": "multiple",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "webapps",
"verified": "0"
} | — | ||||
| Vendor vendor | NVD | cubecartreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "v6",
"vendor": "cubecart",
"versions": [
{
"status": "affected",
"version": "< 6.7.5"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5."
}
],
"id": "CVE-2026-54644",
"lastModified": "2026-09-23T18:12:04.247",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 2.7,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-54644",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T20:02:00.554438Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-17T22:17:02.283",
"references": [
{
"source": "security-advisories@github.com",
"url": "https://github.com/cubecart/v6/blob/6.7.5/admin/sources/release_notes/6.7.5.inc.php"
},
{
"source": "security-advisories@github.com",
"url": "https://github.com/cubecart/v6/commit/7c4c0081fd346578a95738f480ef647116ee1c82"
},
{
"source": "security-advisories@github.com",
"url": "https://github.com/cubecart/v6/releases/tag/6.7.5"
},
{
"source": "security-advisories@github.com",
"url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-79"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Verified verified | Exploit-DB | falsereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Mikail KOCADAĞ",
"codes": "CVE-2026-54644",
"date_added": "2026-08-31",
"date_published": "2026-08-31",
"date_updated": "2026-08-31",
"description": "CubeCart 6.7.4 - Cross-Site Scripting",
"file": "exploits/multiple/webapps/52661.txt",
"id": "52661",
"platform": "multiple",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "webapps",
"verified": "0"
} | — |
vulnerability
exploit
| CubeCart 6.7.4 - Cross-Site Scripting zetlyn/cve-exploitdb · 2026-08-31 | author Mikail KOCADAĞ platform multiple type webapps verified false | source |