CVE-2024-34832: Cubecart

Critical severity, CVSS 9.8. EPSS: 5% chance of exploitation in the next 30 days.

Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node parameters.

Affected products

  • Cubecart Cubecart: before 6.5.5 (fixed in 6.5.5)

Published 2024-06-06. Last modified 2026-06-17.