CVE-2025-59412

MEDIUM

CubeCart < 6.5.11 - Stored Cross-Site Scripting in Product Review Description

Title source: llm
STIX 2.1

Description

CubeCart is an ecommerce software solution. Prior to version 6.5.11, a vulnerability exists in the product reviews feature where user-supplied input is not properly sanitized before being displayed. An attacker can submit HTML tags inside the review description field. Once the administrator approves the review, the injected HTML is rendered on the product page for all visitors. This could be used to redirect users to malicious websites or to display unwanted content. This issue has been patched in version 6.5.11.

Scores

CVSS v3 5.4
EPSS 0.0026
EPSS Percentile 17.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
cubecart/cubecart < 6.5.11
Published Sep 22, 2025
Tracked Since Feb 18, 2026