CVE-2024-33438: Cubecart
High severity, CVSS 8.0. EPSS: 1.1% chance of exploitation in the next 30 days.
File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file.
Affected products
- Cubecart Cubecart: before 6.5.5 (fixed in 6.5.5)
Published 2024-04-29. Last modified 2026-06-17.