CVE-2026-39358 HIGH

CVE-2026-39358: CubeCart: Time-based Blind SQL Injection

Vendor Cubecart
Product v6
Weakness CWE-89 · SQLi
Published May 13, 2026
Last update May 14, 2026

CVSS base score

7.2/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

CubeCart is an ecommerce software solution. Prior to 6.6.0, Authenticated Time-Based Blind SQL Injection vulnerabilities were identified in the sorting parameters (sort[price], sort_activity, sort_admin, and sort_customer) of the Products and Logs endpoints in CubeCart v6.x. This allows an attacker to execute arbitrary SQL commands, compromising the confidentiality and integrity of the database. This vulnerability is fixed in 6.6.0.

Key dates

02Disclosure timeline

May 13, 2026 CVE published
May 14, 2026 Record updated