SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityReceived

CVE-2026-54645

An administrator with product-editing rights can store event-handler attributes, SVG content, or javascript: URIs that bypass this filter, causing persistent JavaScript execution when a storefront visitor or another administrator views the product…

EXPLOITMEDIUM 4.8EPSS 1.26%

Does this matter?

A public exploit is published in Exploit-DB, so the technical barrier is gone even though the severity is medium and EPSS is 1.3%. Treat it as high on anything reachable from the internet.

Description

CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, description_short, and spec_copy rich-text fields from $GLOBALS['RAW']['POST'] and removes only script elements before the values are stored and rendered through Smarty templates. An administrator with product-editing rights can store event-handler attributes, SVG content, or javascript: URIs that bypass this filter, causing persistent JavaScript execution when a storefront visitor or another administrator views the product content and enabling session exposure or unauthorized browser-context actions. This issue is fixed in version 6.7.5.

CVSS 3.1
4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS
1.26% probability · 68th percentile
Public exploits
1 in Exploit-DB · first 31 August 2026
CISA KEV
Not listed
Weakness
CWE-79
Source
security-advisories@github.com
EPSS trend
0%3%5%19 September 2026: 1.26%19 September 202619 September 2026

EPSS 1.3% since 19 September 2026; no change recorded yet. Points are recorded when the score first appears and whenever it moves by a percentage point or more.

Public exploits (1)

Entries in Exploit-DB that cite this CVE. Links go to the Exploit-DB page and to the file in the public repository; nothing is hosted here. A verified tick means the Exploit-DB team confirmed the exploit works against the stated version.

EDB-IDTitleTypePublishedVerified
EDB-52662source ↗CubeCart 6.7.4 - Stored XSSmultiple · Mikail KOCADAĞwebapps31 August 2026no

Source: NVD record, EPSS from FIRST.org, KEV from CISA, exploits from Exploit-DB. Refreshed daily. Download this record as JSON.