Products: 16
    Vulnerabilities: 40
    Known Exploited: 0
    2
    Critical Level Threats
    8
    High Level Threats
    29
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-30777

    Multi‑Factor Authentication Bypass in EC‑Cube Administrator Login

    Last Modified: Apr 16, 2026
    Published: Mar 05, 2026

    CVE-2024-41924

    Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4 series. If this vulnerability is exploited, an attacker who obtained the administrative privilege may install an arbitrary PHP package. If the obsolete versions of PHP packages are installed, the product may be affected by some known vulnerabilities.

    Last Modified: Apr 15, 2026
    Published: Jul 30, 2024

    CVE-2023-46845

    EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to 4.1.2-p2, and 4.2.0 to 4.2.2) contain an arbitrary code execution vulnerability due to improper settings of the template engine Twig included in the product. As a result, arbitrary code may be executed on the server where the product is running by a user with an administrative privilege.

    Last Modified: Nov 21, 2024
    Published: Nov 07, 2023

    CVE-2023-40281

    EC-CUBE 2.11.0 to 2.17.2-p1 contain a cross-site scripting vulnerability in "mail/template" and "products/product" of Management page. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the other administrator or the user who accessed the website using the product.

    Last Modified: Nov 21, 2024
    Published: Aug 17, 2023

    CVE-2023-25077

    Cross-site scripting vulnerability in Authentication Key Settings of EC-CUBE 4.0.0 to 4.0.6-p2, EC-CUBE 4.1.0 to 4.1.2-p1, and EC-CUBE 4.2.0 allows a remote authenticated attacker to inject an arbitrary script.

    Last Modified: Mar 06, 2025
    Published: Mar 05, 2023
    Items Per Page
    Ec-Cube Vulnerabilities & Security CVEs | CVE-DB