CubeCart Hosting
CubeCart optimised hosting free for 14 days.
Fast and secure without the middleman.
Download
Self manage on 3rd party Linux web hosting.
License: GPL 3.0 • GitHub: cubecart/v6
What is CubeCart?
Whether you are a retailer looking for an online store or a webmaster seeking an ecommerce solution for a client… CubeCart is a powerful free ecommerce solution enabling thousands of merchants globally to sell digital or physical products online.
Latest News
14 Day Trial & Free Migration on all Official CubeCart Hosting Plans
We are offering a 14 day free trial on all web hosting plans including free migration from your existing web host. We'll even upgrade your store to the latest version at no extra cost!
Our hosting is specially optimised for CubeCart stores which include;
- lightening fast dedicated memory caching.
- elasticsearch for search as you type functionality.
- the best CubeCart technical support direct from our developers.
No more hosting middle man! Come and give us a try.
Sign up now at https://hosted.cubecart.com
Permalink | 14th May 2024 11:31
CubeCart 6.5.5 Released - Minor Security Update
This release of CubeCart not only resolves a number of stability issues found in the previous version but patches a minor security vulnerability. We are grateful and thankful to Julio Araujo for reporting this so clearly and responsibly.
The security patch (GitHub issue #3570) prevents malicious .phar type files from being uploaded via the back office of the store. Please note that a bad actor would need to have successfully authenticated into the back office in order to take advantage of this vulnerability. On those grounds we do not consider this to be a significant threat.
To patch this vulnerability please either upgrade to CubeCart 6.5.5 or amend the code in the security patch linked above.
Download: CubeCart-6.5.5.zip
Permalink | 24th April 2024 13:49
CubeCart 6.5.4 Released
We are please to announce the release of CubeCart 6.5.4. This is a maintenance release with a number of minor new features.
Important Release Notes
This version converts the database encoding to utf8mb4. Please make sure that your installation of MySQL or MariaDB supports this character set. *
Download: CubeCart-6.5.4
The table below shows the new features added to this release. All 95 closed issues can be found on GitHub.
Issue | New Feature |
---|---|
#3543 |
List view aded to filemanager.
|
#3544 | Sorter added to filemanager for name, date added and filesize (see screenshot above). |
#3536 | reCaptcha added to password recovery tool. |
#3532 | Customer comments icon with link added to dashboard orders (unsettled orders) list. |
#3525 | Bulk action to add/remove orders from dashboard (unsettled orders). |
#3488 | Use of hooks to manipulate dashboard (unsettled orders) bulk actions. |
#3487 | Order list to have new "Last Updated" column with sorter. |
#3447 | Preview icon on category and document list to view on front end. |
#3427 | Switch to allow for product and category descriptions to be parsed via Smarty (for dynamic contnt). |
#3425 | Improved character set support utf8mb3 to utf8mb4 |
#3424 |
Exchange rate "buffer" with percentage adjustment.
|
#3418 | Order summary to show both custom order ID (if available) and traditional order ID. |
#3413 | Filemanager last location memory for product option images |
#3392 |
Adjust product sales report by date.
|
#3385 | Switch off order email whilst in PayPal Sandbox mode (PayPal Commerce 1.9.5+ required). |
#3420 |
Rich Text Editor - Emoji Picker Plugin
|
* It is possible to list available UTF8 character sets with the MySQL command:
SHOW CHARACTER SET LIKE 'utf8%';
Permalink | 15th April 2024 08:59
CubeCart 6.5.3 Released - Security Update
Many thanks to Gen Sato from Mitsui Bussan Secure Directions, Inc. for responsibly reporting a number of security issues found in all version of CubeCart up to 6.5.3. Please note that these vulnerabilities are executable if a bad actor has authenticated into the back end of the victims store.
Vulnerabilities
- Directory traversal (any file download) - GitHub Issue #3410
- Directory traversal (deletion of arbitrary files and directories) - GitHub Issue #3409
- CSRF bypassing CSRF token checks - GitHub Issue #3408
-
OS Command Injection - This vulnerability concerns the ability for the Smarty template engine to be able to execute dangerous functions.
e.g.{system('echo ^<?php phpinfo(); > C:/xampp/htdocs/testout.php')}
No patch has been created for this vulnerability but instead we strongly recommend disabling dangerous PHP functions as recommended by our free CubeCart Security Suite. We suggest disabling the following PHP functions with your php.ini file then restarting the web server.
disable_functions = exec, system, passthru, pcntl_exec, popen, proc_open, shell_exec
This release also patches a number of other maintenance updates.
Upgrading to 6.5.3 is highly recommended. If for some reason you are unable to upgrade to this version it is possible to find the code patches for each vulnerability within each GitHub issue above. If you require help, technical support is available.
Download: CubeCart-6.5.3.zip
Permalink | 30th October 2023 10:40
CubeCart 6.5.2 Released
We are pleased to announce the release of 6.5.2.
What's New?
#3304 | Back-office 404 log. Discover external URL's that have no destination and use the existing redirect tool to fix them. |
#3131 | Back-office category list now shows product count. |
#3229 | Escape key now closes back office search pull out. |
#3243 | Memory added to back office list size (Products, Orders, Customers). |
#3275 | Administrator log to show more detailed info. e.g. The item that was edited. |
#3299 | Improved back office request log layout with header logging. |
#3331 | "Save & Reload" button added to category edit add/page. |
#3332 | Google Universal Analytics removed in favour of new extension. |
#3346 | Back-office customer list to show their chosen language. |
#3347 | hCaptcha officially supported as an alternative to Google reCAPTCHA. This requires skin updates. |
#3348 | Back-office now logs actions of cleaning subscriber log. |
See all 112 closed issues for this version.
Download: CubeCart-6.5.2.zip
Need help upgrading or require official technical support? Find out more at https://www.cubecart.com/technical-support