{"id":"CVE-2026-54645","url":"https://www.cyber-defence.io/tools/cve/CVE-2026-54645","generatedAt":"2026-09-20T15:04:42.818Z","title":"An administrator with product-editing rights can store event-handler attributes, SVG content, or javascript: URIs that bypass this filter, causing persistent JavaScript execution when a storefront visitor or another administrator views the product…","description":"CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, description_short, and spec_copy rich-text fields from $GLOBALS['RAW']['POST'] and removes only script elements before the values are stored and rendered through Smarty templates. An administrator with product-editing rights can store event-handler attributes, SVG content, or javascript: URIs that bypass this filter, causing persistent JavaScript execution when a storefront visitor or another administrator views the product content and enabling session exposure or unauthorized browser-context actions. This issue is fixed in version 6.7.5.","published":"2026-09-17T22:17:02.000Z","lastModified":"2026-09-17T22:17:02.000Z","status":"Received","sourceIdentifier":"security-advisories@github.com","cvss":{"version":"3.1","score":4.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"},"cwe":["CWE-79"],"affected":[],"epss":{"score":0.01265,"percentile":0.68413,"date":"2026-09-19","history":[]},"kev":{"listed":false},"exploits":{"count":1,"verified":false,"firstPublished":"2026-08-31","source":"Exploit-DB (https://gitlab.com/exploit-database/exploitdb)","entries":[{"edbId":52662,"kind":"exploit","title":"CubeCart 6.7.4 - Stored XSS","url":"https://www.exploit-db.com/exploits/52662","sourceUrl":"https://gitlab.com/exploit-database/exploitdb/-/blob/main/exploits/multiple/webapps/52662.txt","file":"exploits/multiple/webapps/52662.txt","published":"2026-08-31","added":"2026-08-31","updated":"2026-08-31","author":"Mikail KOCADAĞ","type":"webapps","platform":"multiple","port":null,"verified":false,"codes":["CVE-2026-54645"],"tags":null,"aliases":null,"applicationUrl":null,"screenshotUrl":null,"referenceUrl":null}]},"verdict":{"level":"high","text":"A public exploit is published in Exploit-DB, so the technical barrier is gone even though the severity is medium and EPSS is 1.3%. Treat it as high on anything reachable from the internet."},"changes":[{"kind":"exploit","label":"Public exploit","at":"2026-08-31T00:00:00.000Z","detail":{"type":"webapps","edbId":52662,"title":"CubeCart 6.7.4 - Stored XSS","platform":"multiple","verified":false,"publishedAt":"2026-08-31"},"summary":"Public exploit published in Exploit-DB: CubeCart 6.7.4 - Stored XSS (webapps, multiple)."}],"references":[{"url":"https://github.com/cubecart/v6/blob/6.7.5/admin/sources/release_notes/6.7.5.inc.php","source":"security-advisories@github.com"},{"url":"https://github.com/cubecart/v6/commit/bd2dcdcc7da55a3731fe288b54cac8bfa3d9142a","source":"security-advisories@github.com"},{"url":"https://github.com/cubecart/v6/commit/f7abe7484691a33abcbc0806fca59d605024a75c","source":"security-advisories@github.com"},{"url":"https://github.com/cubecart/v6/releases/tag/6.7.5","source":"security-advisories@github.com"},{"url":"https://github.com/cubecart/v6/security/advisories/GHSA-43f6-gfcf-wj9c","source":"security-advisories@github.com"}],"sources":{"nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-54645","epss":"https://www.first.org/epss/","kev":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","exploitdb":"https://www.exploit-db.com/"},"licence":"CC BY 4.0 — link back to the CVE Explorer if you publish the results; upstream data remains subject to its own terms."}