Unauthenticated Reflected XSS Vulnerability in CubeCart E-commerce Software
CVE-2026-44376

6.1MEDIUM

Key Information:

Vendor

Cubecart

Status
Vendor
CVE Published:
13 May 2026

What is CVE-2026-44376?

CubeCart, a popular e-commerce solution, has a vulnerability in its search feature prior to version 6.7.0 that allows unauthenticated attackers to exploit a reflected cross-site scripting (XSS) flaw. This occurs through a logic issue in the application where user input is reflected back without proper sanitization, but only when a single product is returned in search results. The lack of sufficient filters enables the injection of malicious JavaScript, which could lead to severe outcomes such as session hijacking, site defacement, and phishing attempts on unsuspecting users. The issue has been resolved in version 6.7.0.

Affected Version(s)

v6 < 6.7.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.