CVE-2026-21719

· NIST NVD ↗

An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to execute an arbitrary OS command.

HIGH
CVSS severity
7.2
CVSS base score
2026-04-17
Published

CWE codes

CWE-78

Affected products

cubecart:cubecart

Sources