CVE-2018-20716: Cubecart

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature.

Affected products

  • Cubecart Cubecart: before 6.1.13 (fixed in 6.1.13)

Published 2019-01-15. Last modified 2026-06-17.