CVE-2013-1465: Cubecart

Critical severity, CVSS 9.8. EPSS: 7.1% chance of exploitation in the next 30 days.

The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objects via a crafted shipping parameter, as demonstrated by modifying the application configuration using the Config object.

Affected products

  • Cubecart Cubecart: from 5.0.0, up to and including 5.2.0

Published 2013-02-08. Last modified 2026-06-16.