CVE-2025-59413: Cubecart

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

CubeCart is an ecommerce software solution. Prior to version 6.5.11, a logic flaw exists in the newsletter subscription endpoint that allows an attacker to unsubscribe any user without their consent. By changing the value of the force_unsubscribe parameter in the POST request to 1, an attacker can force the removal of any valid subscriber’s email address. This issue has been patched in version 6.5.11.

Affected products

  • Cubecart Cubecart: before 6.5.11 (fixed in 6.5.11)

Published 2025-09-22. Last modified 2026-06-17.