Persistent JavaScript Execution Vulnerability in CubeCart E-commerce Software
CVE-2026-54645

4.8MEDIUM

Key Information:

Vendor

Cubecart

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54645?

CubeCart, an e-commerce software solution, contains a vulnerability within its product editing feature that allows an administrator with editing rights to insert JavaScript code, including event-handler attributes, SVG content, or javascript: URIs, into product descriptions. This flaw occurs as the software inadequately sanitizes user input in certain rich-text fields before rendering the content on storefronts. If exploited, this could lead to persistent JavaScript execution, exposing user sessions or enabling unauthorized actions within the browser context. The issue has been addressed in version 6.7.5, which implements stricter input validation and sanitization mechanisms.

Affected Version(s)

v6 < 6.7.5

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.