CVE-2023-46845: Ec-Cube

High severity, CVSS 7.2. EPSS: 1.6% chance of exploitation in the next 30 days.

EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to 4.1.2-p2, and 4.2.0 to 4.2.2) contain an arbitrary code execution vulnerability due to improper settings of the template engine Twig included in the product. As a result, arbitrary code may be executed on the server where the product is running by a user with an administrative privilege.

Affected products

  • Ec-Cube Ec-Cube: from 3.0.0, up to and including 3.0.18; from 4.0.0, up to and including 4.0.6; from 4.1.0, up to and including 4.1.2; from 4.2.0, before 4.2.3 (fixed in 4.2.3); version 3.0.18 only; version 4.0.6 only; …

Published 2023-11-07. Last modified 2026-06-17.