CVE-2026-21719: Cubecart

High severity, CVSS 8.6. EPSS: 1.2% chance of exploitation in the next 30 days.

An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to execute an arbitrary OS command.

Affected products

  • Cubecart Cubecart: before 6.6.0 (fixed in 6.6.0)

Published 2026-04-17. Last modified 2026-06-17.