CVE-2014-9026: Ubercart
Medium severity, CVSS 4.0. EPSS: 0.9% chance of exploitation in the next 30 days.
The Ubercart module 7.x-3.x before 7.x-3.7 for Drupal does not properly protect the per-user order history view, which allows remote authenticated users with the "view own orders" permission to obtain sensitive information via unspecified vectors.
Affected products
- Ubercart Ubercart: version 7.x-3.0 only; version 7.x-3.1 only; version 7.x-3.2 only; version 7.x-3.3 only; version 7.x-3.4 only; version 7.x-3.5 only; …
Published 2014-11-20. Last modified 2026-06-17.