Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
66 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.59% | — | CubecartAI | 17/9/2026 | 23/9/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the GDPR tools in admin/sources/customers.gdpr.inc.php rely on page-level CC_PERM_READ access and do not require CC_PERM_DELETE for the purge, no_order_purge, or delete_guests commands. An authenticated administrator with read-only customer privileges can… | |
| Aplazada | Alta (7.2) | 1.4% | — | CubecartAI | 17/9/2026 | 24/9/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates the administrator-controlled download_expire POST parameter into a raw UPDATE statement for CubeCart_downloads without numeric validation. An authenticated administrator can supply a comma-delimited… | |
| Aplazada | Alta (7.2) | 1.4% | — | CubecartAI | 17/9/2026 | 23/9/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator-controlled tablename values into ALTER TABLE, CHECK TABLE, and ANALYZE TABLE statements without validating the identifiers or escaping embedded backticks. An authenticated administrator can… | |
| Aplazada | Media (4.8) | 1.1% | — | CubecartAI | 17/9/2026 | 24/9/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, description_short, and spec_copy rich-text fields from $GLOBALS['RAW']['POST'] and removes only script elements before the values are stored and rendered through Smarty templates. An administrator… | |
| Pendiente de análisis | Media (6.1) | 0.90% | — | CubecartAI | 17/9/2026 | 23/9/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI… | |
| Aplazada | Media (5.4) | 0.38% | — | CubecartAI | 17/9/2026 | 23/9/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete-note handler in admin/sources/orders.index.inc.php verifies only the presence of order_id and delete-note parameters before deleting records from CubeCart_order_notes, without requiring CC_PERM_DELETE for orders. An authenticated administrator… | |
| Aplazada | Media (5.3) | 0.33% | — | CubecartAI | 17/9/2026 | 24/9/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored-payment-card action in admin/sources/orders.index.inc.php use state-changing GET requests and are omitted from the protection map in admin/skins/default/csrf.inc.php. A remote attacker can induce an… | |
| Aplazada | Crítica (9.1) | 0.54% | — | CubecartAI | 13/5/2026 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates, Invoices, Documents, and Contact Forms). The application unsafely evaluates user-supplied input using the Smarty template… | |
| Aplazada | Alta (7.2) | 0.54% | — | CubecartAI | 13/5/2026 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.3, an admin with documents edit permission can save raw <?php … ?> into the Invoice Editor. The next time any admin clicks Print on any order, the rendered template is written to files/print.<md5>.php. files/.htaccess ships an explicit <Files print.*.php> allow… | |
| Aplazada | Alta (8.1) | 0.20% | — | CubecartAI | 13/5/2026 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the Host request header at bootstrap, with no allowlist. The constant is embedded verbatim into transactional email links, most critically the password-reset link in User::passwordRequest() (and the… | |
| Aplazada | Media (4.9) | 0.40% | — | CubecartAI | 13/5/2026 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.0, the admin orders-transactions listing page (admin.php?_g=orders&node=transactions) builds a raw ORDER BY SQL fragment from the attacker-controlled $_GET['sort'] array without column or direction validation. Both the column key and the direction value flow… | |
| Aplazada | Crítica (9.1) | 0.76% | — | CubecartAI | 13/5/2026 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists in the REST API File Manager endpoint (POST /api/v1/files) of CubeCart. The endpoint allows any holder of an API key with files:rw permission to upload PHP source files into the web-accessible… | |
| Aplazada | Crítica (9.1) | 0.96% | — | CubecartAI | 13/5/2026 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates and Documents). The application unsafely evaluates user-supplied input directly through the Smarty template engine. By… | |
| Aplazada | Media (6.1) | 0.69% | — | CubecartAI | 13/5/2026 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.0, an unauthenticated Reflected XSS vulnerability exists in the CubeCart v6.x search feature. Due to a logic flaw in classes/catalogue.class.php, user input is reflected without sanitization only when a search returns exactly one product. This flaw bypasses… | |
| Aplazada | Media (4.8) | 0.24% | — | CubecartAI | 13/5/2026 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to 6.6.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in CubeCart v6.x. An attacker with administrative privileges can inject malicious JavaScript payloads into multiple fields during the creation or modification of a product. These payloads are stored in… | |
| Aplazada | Alta (7.2) | 0.45% | — | CubecartAI | 13/5/2026 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to 6.6.0, Authenticated Time-Based Blind SQL Injection vulnerabilities were identified in the sorting parameters (sort[price], sort_activity, sort_admin, and sort_customer) of the Products and Logs endpoints in CubeCart v6.x. This allows an attacker to execute… | |
| Analizada | Media (5.1) | 0.44% | — | Cubecart | 17/4/2026 | 17/6/2026 | A path traversal vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to access higher-level directories that should not be accessible. | |
| Analizada | Media (5.1) | 0.33% | — | Cubecart | 17/4/2026 | 17/6/2026 | An SQL injection vulnerability exists in CubeCart prior to 6.6.0, which may allow an attacker to execute an arbitrary SQL statement on the product. | |
| Analizada | Alta (8.6) | 1.2% | — | Cubecart | 17/4/2026 | 17/6/2026 | An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to execute an arbitrary OS command. | |
| Analizada | Media (6.5) | 0.40% | — | Cubecart | 22/9/2025 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to version 6.5.11, a logic flaw exists in the newsletter subscription endpoint that allows an attacker to unsubscribe any user without their consent. By changing the value of the force_unsubscribe parameter in the POST request to 1, an attacker can force the removal of… | |
| Analizada | Media (5.4) | 0.28% | — | Cubecart | 22/9/2025 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to version 6.5.11, a vulnerability exists in the product reviews feature where user-supplied input is not properly sanitized before being displayed. An attacker can submit HTML tags inside the review description field. Once the administrator approves the review, the… | |
| Analizada | Media (5.4) | 0.30% | — | Cubecart | 22/9/2025 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to version 6.5.11, the contact form’s Enquiry field accepts raw HTML and that HTML is included verbatim in the email sent to the store admin. By submitting HTML in the Enquiry, the admin receives an email containing that HTML. This indicates user input is not being… | |
| Analizada | Alta (7.1) | 0.20% | — | Cubecart | 22/9/2025 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration following a user's password change. This oversight poses a security risk, as if a user forgets to log out from a location where they accessed their account, an unauthorized user can maintain access… | |
| Modificada | Crítica (9.8) | 5.0% | — | Cubecart | 6/6/2024 | 17/6/2026 | Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node parameters. | |
| Analizada | Alta (8) | 1.1% | — | Cubecart | 29/4/2024 | 17/6/2026 | File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file. |