Report: CVE-2026-44376 - CubeCart: Reflected XSS in Store Search Bar

Report: CVE-2026-44376 - CubeCart: Reflected XSS in Store Search Bar

CVE ID :CVE-2026-44376 Published : May 13, 2026, 9:16 p.m. | 31 minutes ago Description :CubeCart is an ecommerce software solution. Prior to 6.7.0, an unauthenticated Reflected XSS vulnerability exists in the CubeCart v6.x search feature. Due to a logic flaw in classes/catalogue.class.php, user input is reflected without sanitization only when a search returns exactly one product. This flaw bypasses current filters, allowing an attacker to execute malicious JavaScript in the victim's browser, leading to session hijacking, site defacement, or phishing. This vulnerability is fixed in 6.7.0. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
May 13, 2026
Affected Product: php
Impact: XSS