CVE-2023-42428: Cubecart

Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.

Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to delete directories and files in the system.

Affected products

  • Cubecart Cubecart: before 6.5.3 (fixed in 6.5.3)

Published 2023-11-17. Last modified 2026-06-17.