CVE-2026-45714

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates, Invoices, Documents, and Contact Forms). The application unsafely evaluates user-supplied input using the Smarty template engine without enabling Smarty Security Policies. This allows any authenticated user with administrative privileges to execute arbitrary operating system commands (RCE) on the server. This vulnerability is fixed in 6.7.0.
Configurations

No configuration.

History

14 May 2026, 16:16

Type Values Removed Values Added
References () https://github.com/cubecart/v6/security/advisories/GHSA-pcfr-xgc9-xfv6 - () https://github.com/cubecart/v6/security/advisories/GHSA-pcfr-xgc9-xfv6 -

13 May 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-13 21:16

Updated : 2026-05-14 16:49


NVD link : CVE-2026-45714

Mitre link : CVE-2026-45714

CVE.ORG link : CVE-2026-45714


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine