CVE-2018-20716: Cubecart
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature.
Affected products
- Cubecart Cubecart: before 6.1.13 (fixed in 6.1.13)
Published 2019-01-15. Last modified 2026-06-17.