PatchSiren

cubecart CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM cubecart CVE published 2026-09-17

CVE-2026-54645

CubeCart 6.7.4 and earlier versions have a stored cross-site scripting (XSS) vulnerability in the product description, short description, and spec_copy fields. An administrator with product-editing rights can store malicious JavaScript code that bypasses the filter, leading to persistent JavaScript execution when a storefront visitor or another administrator views the product content.