← back
CVE-2026-45714

CubeCart: Server-Side Template Injection (SSTI) in Smarty Templates leading to RCE

CVSS 9.1 CRITICALEPSS 0.4%CWE-1336CWE-94
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.1EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
13 May 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates, Invoices, Documents, and Contact Forms). The application unsafely evaluates user-supplied input using the Smarty template engine without enabling Smarty Security Policies. This allows any authenticated user with administrative privileges to execute arbitrary operating system commands (RCE) on the server. This vulnerability is fixed in 6.7.0.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected products
cubecart · v6

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →