MEDIUM
cubecart
CVE published 2026-09-17
CVE-2026-54645
CubeCart 6.7.4 and earlier versions have a stored cross-site scripting (XSS) vulnerability in the product description, short description, and spec_copy fields. An administrator with product-editing rights can store malicious JavaScript code that bypasses the filter, leading to persistent JavaScript execution when a storefront visitor or another administrator views the product content.