Description
CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates, Invoices, Documents, and Contact Forms). The application unsafely evaluates user-supplied input using the Smarty template engine without enabling Smarty Security Policies. This allows any authenticated user with administrative privileges to execute arbitrary operating system commands (RCE) on the server. This vulnerability is fixed in 6.7.0.
Published: 2026-05-13
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CubeCart versions prior to 6.7.0 contain an authenticated server‑side template injection flaw in several modules such as Email Templates, Invoices, Documents, and Contact Forms. The application evaluates user‑supplied data through the Smarty template engine without enabling its security policies, allowing an authenticated administrator to embed and execute arbitrary operating‑system commands on the hosting server. This results in full compromise of confidentiality, integrity, and availability of the affected system. The weakness is categorized as code injection (CWE‑94) and server‑side template injection (CWE‑1336).

Affected Systems

Any installation of CubeCart v6 dated before the 6.7.0 release, where the affected modules are enabled for administrative modification, is vulnerable. Products explicitly listed by the CNA include CubeCart v6 in its entirety; no specific sub‑version restrictions were provided other than the requirement to be older than 6.7.0.

Risk and Exploitability

The CVSS score of 9.1 indicates extreme severity. At the time of this analysis the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access and administrative privileges; once these credentials are obtained, an attacker can freely inject template code to execute system commands. Due to the high severity and the straightforward exploitation path once authenticated, the risk to vulnerable installations is very high.

Generated by OpenCVE AI on May 13, 2026 at 22:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade CubeCart to version 6.7.0 or later, which removes the unsafe template handling.
  • If an upgrade is delayed, remove or disable administrative access to the affected modules (Email Templates, Invoices, Documents, Contact Forms) that allow custom template editing.
  • Configure Smarty’s security policies or disable dynamic template evaluation for user‑supplied content to prevent injection when legacy code must remain in place.

Generated by OpenCVE AI on May 13, 2026 at 22:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 14 May 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 14 May 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Cubecart
Cubecart cubecart
Vendors & Products Cubecart
Cubecart cubecart

Wed, 13 May 2026 21:15:00 +0000

Type Values Removed Values Added
Description CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates, Invoices, Documents, and Contact Forms). The application unsafely evaluates user-supplied input using the Smarty template engine without enabling Smarty Security Policies. This allows any authenticated user with administrative privileges to execute arbitrary operating system commands (RCE) on the server. This vulnerability is fixed in 6.7.0.
Title CubeCart: Server-Side Template Injection (SSTI) in Smarty Templates leading to RCE
Weaknesses CWE-1336
CWE-94
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cubecart Cubecart
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-05-14T15:51:08.463Z

Reserved: 2026-05-13T05:51:48.666Z

Link: CVE-2026-45714

cve-icon Vulnrichment

Updated: 2026-05-14T15:50:37.383Z

cve-icon NVD

Status : Deferred

Published: 2026-05-13T21:16:50.020

Modified: 2026-05-14T16:49:18.583

Link: CVE-2026-45714

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-14T14:33:19Z

Weaknesses