CVE-2024-33438: Cubecart

High severity, CVSS 8.0. EPSS: 1.1% chance of exploitation in the next 30 days.

File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file.

Affected products

  • Cubecart Cubecart: before 6.5.5 (fixed in 6.5.5)

Published 2024-04-29. Last modified 2026-06-17.