CVE-2026-34018

CRITICAL

CubeCart < prior to 6.6.0 - SQL Injection

Title source: rule
STIX 2.1

Description

An SQL injection vulnerability exists in CubeCart prior to 6.6.0, which may allow an attacker to execute an arbitrary SQL statement on the product.

Scores

CVSS v3 9.8
EPSS 0.0003
EPSS Percentile 9.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (2)
cubecart/cubecart < 6.6.0
CubeCart Limited/CubeCart prior to 6.6.0
Published Apr 17, 2026
Tracked Since Apr 17, 2026