CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5.

zetlyn/cve-nvd vulnerability cve CVE-2026-54644 known 2026-09-17

https://nvd.nist.gov/vuln/detail/CVE-2026-54644

Properties

cvss6.1
receipt
Source
NVD
Its words
6.1
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-05 18:25 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "v6",
            "vendor": "cubecart",
            "versions": [
              {
                "status": "affected",
                "version": "< 6.7.5"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5."
      }
    ],
    "id": "CVE-2026-54644",
    "lastModified": "2026-09-23T18:12:04.247",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.7,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-54644",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T20:02:00.554438Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-17T22:17:02.283",
    "references": [
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/blob/6.7.5/admin/sources/release_notes/6.7.5.inc.php"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/commit/7c4c0081fd346578a95738f480ef647116ee1c82"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/releases/tag/6.7.5"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Awaiting Analysis",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
productv6
receipt
Source
NVD
Its words
v6
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-05 18:25 UTC
Original
open at the source
2026-09-29 17:49 UTCv6
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "v6",
            "vendor": "cubecart",
            "versions": [
              {
                "status": "affected",
                "version": "< 6.7.5"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5."
      }
    ],
    "id": "CVE-2026-54644",
    "lastModified": "2026-09-23T18:12:04.247",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.7,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-54644",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T20:02:00.554438Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-17T22:17:02.283",
    "references": [
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/blob/6.7.5/admin/sources/release_notes/6.7.5.inc.php"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/commit/7c4c0081fd346578a95738f480ef647116ee1c82"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/releases/tag/6.7.5"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Awaiting Analysis",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
statusAwaiting Analysis
receipt
Source
NVD
Its words
Awaiting Analysis
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-05 18:25 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "v6",
            "vendor": "cubecart",
            "versions": [
              {
                "status": "affected",
                "version": "< 6.7.5"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5."
      }
    ],
    "id": "CVE-2026-54644",
    "lastModified": "2026-09-23T18:12:04.247",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.7,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-54644",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T20:02:00.554438Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-17T22:17:02.283",
    "references": [
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/blob/6.7.5/admin/sources/release_notes/6.7.5.inc.php"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/commit/7c4c0081fd346578a95738f480ef647116ee1c82"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/releases/tag/6.7.5"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Awaiting Analysis",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
vendorcubecart
receipt
Source
NVD
Its words
cubecart
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-05 18:25 UTC
Original
open at the source
2026-09-29 17:49 UTCcubecart
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "v6",
            "vendor": "cubecart",
            "versions": [
              {
                "status": "affected",
                "version": "< 6.7.5"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5."
      }
    ],
    "id": "CVE-2026-54644",
    "lastModified": "2026-09-23T18:12:04.247",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.7,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-54644",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T20:02:00.554438Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-17T22:17:02.283",
    "references": [
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/blob/6.7.5/admin/sources/release_notes/6.7.5.inc.php"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/commit/7c4c0081fd346578a95738f480ef647116ee1c82"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/releases/tag/6.7.5"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "url": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Awaiting Analysis",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}

Text

CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5.