VULNERABILITY INTELLIGENCE
CVE-2026-45708
CVSS score7.2 HIGH
EPSS probability0.54%
CISA KEVNot currently listed
Published2026-05-13
Last modified2026-06-17
Description
CubeCart is an ecommerce software solution. Prior to 6.7.3, an admin with documents edit permission can save raw <?php … ?> into the Invoice Editor. The next time any admin clicks Print on any order, the rendered template is written to files/print.<md5>.php. files/.htaccess ships an explicit <Files ... .