PT-2026-33409 · Cubecart · Cubecart

Published

2026-04-17

·

Updated

2026-04-17

·

CVE-2026-34018

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CubeCart versions prior to 6.6.0
Description An SQL injection allows an attacker to execute arbitrary SQL statements on the product.
Recommendations Update to version 6.6.0.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-34018

Affected Products

Cubecart