The number one free & open source eCommerce system.
"Simply the best. I have installed them all and used them all. CubeCart is it."Investr
CubeCart Screenshots
  • Open Source

    CubeCart is 100% free and completely customisable.
  • Extend

    A plethora of extensions are available from payment gateways to shipping calculators.
  • Technical Support

    Professional technical support is available directly from our developers.

Hosted

Get an instant CubeCart hosted store free for 14 days.
No risk, and no credit card required.

CubeCart Hosted - 1 month free!

Download

Self manage on 3rd party Linux web hosting.
License: GPL 3.0 • GitHub: cubecart/v6

Download 6.5.4

What is CubeCart?

Whether you are a retailer looking for an online store or a webmaster seeking an ecommerce solution for a client… CubeCart is a powerful free ecommerce solution enabling thousands of merchants globally to sell digital or physical products online.


Latest News

CubeCart 6.5.4 Released

We are please to announce the release of CubeCart 6.5.4. This is a maintenance release with a number of minor new features.

Important Release Notes
This version converts the database encoding to utf8mb4. Please make sure that your installation of MySQL or MariaDB supports this character set. *

Download: CubeCart-6.5.4

The table below shows the new features added to this release. All 95 closed issues can be found on GitHub.

Issue New Feature
#3543
List view aded to filemanager.
issue.3543.png
#3544 Sorter added to filemanager for name, date added and filesize (see screenshot above).
#3536 reCaptcha added to password recovery tool.
#3532 Customer comments icon with link added to dashboard orders (unsettled orders) list.
#3525 Bulk action to add/remove orders from dashboard (unsettled orders).
#3488 Use of hooks to manipulate dashboard (unsettled orders) bulk actions.
#3487 Order list to have new "Last Updated" column with sorter.
#3447 Preview icon on category and document list to view on front end.
#3427 Switch to allow for product and category descriptions to be parsed via Smarty (for dynamic contnt).
#3425 Improved character set support utf8mb3 to utf8mb4
#3424
Exchange rate "buffer" with percentage adjustment.
issue.3424.png
#3418 Order summary to show both custom order ID (if available) and traditional order ID.
#3413 Filemanager last location memory for product option images
#3392
Adjust product sales report by date.
issue.3392.png
#3385 Switch off order email whilst in PayPal Sandbox mode (PayPal Commerce 1.9.5+ required).
#3420
Rich Text Editor - Emoji Picker Plugin
issue.3420.png

 

* It is possible to list available UTF8 character sets with the MySQL command:

SHOW CHARACTER SET LIKE 'utf8%';

Screenshot 2024-04-15 at 09.59.15.png

Permalink | 15th April 2024 08:59


CubeCart 6.5.3 Released - Security Update

Many thanks to Gen Sato from Mitsui Bussan Secure Directions, Inc. for responsibly reporting a number of security issues found in all version of CubeCart up to 6.5.3. Please note that these vulnerabilities are executable if a bad actor has authenticated into the back end of the victims store.

Vulnerabilities

  1. Directory traversal (any file download) - GitHub Issue #3410 
  2. Directory traversal (deletion of arbitrary files and directories) - GitHub Issue #3409
  3. CSRF bypassing CSRF token checks - GitHub Issue #3408
  4. OS Command Injection - This vulnerability concerns the ability for the Smarty template engine to be able to execute dangerous functions.

    e.g. 
    {system('echo ^<?php phpinfo(); > C:/xampp/htdocs/testout.php')}

    No patch has been created for this vulnerability but instead we strongly recommend disabling dangerous PHP functions as recommended by our free CubeCart Security Suite. We suggest disabling the following PHP functions with your php.ini file then restarting the web server. 

    disable_functions = exec, system, passthru, pcntl_exec, popen, proc_open, shell_exec

This release also patches a number of other maintenance updates

Upgrading to 6.5.3 is highly recommended. If for some reason you are unable to upgrade to this version it is possible to find the code patches for each vulnerability within each GitHub issue above. If you require help, technical support is available. 

Download: CubeCart-6.5.3.zip

 

Permalink | 30th October 2023 10:40


CubeCart 6.5.2 Released

We are pleased to announce the release of 6.5.2.

What's New?

#3304 Back-office 404 log. Discover external URL's that have no destination and use the existing redirect tool to fix them.
#3131 Back-office category list now shows product count.
#3229 Escape key now closes back office search pull out.
#3243 Memory added to back office list size (Products, Orders, Customers).
#3275 Administrator log to show more detailed info. e.g. The item that was edited.
#3299 Improved back office request log layout with header logging.
#3331 "Save & Reload" button added to category edit add/page.
#3332 Google Universal Analytics removed in favour of new extension.
#3346 Back-office customer list to show their chosen language.
#3347 hCaptcha officially supported as an alternative to Google reCAPTCHA. This requires skin updates.
#3348 Back-office now logs actions of cleaning subscriber log.

See all 112 closed issues for this version. 

Download: CubeCart-6.5.2.zip

Need help upgrading or require official technical support? Find out more at https://www.cubecart.com/technical-support

Permalink | 1st September 2023 15:53


Apple Pay and other new features are now available with PayPal Commerce!

With advanced features of the latest PayPal integration, you can accept PayPal, Pay Later, and Venmo* — plus Apple Pay®**, local payment methods from around the world, and process all major credit and debit cards.

Offer Apple Pay®**:
Apple Pay® is a fast, simple, and secure way to pay in millions of places online and in-store. It’s built into Apple Wallet® and available on eligible Apple® devices.

Save payment details:
Automatically save customer card, billing, and shipping info for a fast, convenient checkout experience. This feature means returning shoppers don't have to re-enter payment information on future purchases — making for a simpler checkout that can help drive conversion.

Real-time account updater services:
When a replacement card is issued to a customer, real-time account updater services automatically update that new card information on the backend and helps reduce chances you’ll miss a sale due to customer stolen, lost, or expired cards.

Get more transparency with IC++ (US Only):
Interchange Plus Plus (IC++) is a pricing model that credit card processors use to calculate the fees associated with each transaction. Compared to flat-rate pricing, IC++ offers an added layer of transparency for eligible merchants. Learn more about IC++.

Competitive transaction fees:
Card processing fees that are competitively priced for the marketplace.  Apple Pay® does not charge any additional fees.

How to enable ApplePay in CubeCart
Install our free PayPal Commerce extension. From the extension configuration page, check the box next to Apple Pay. Follow the instructions from there to enable Apple Pay.


* Venmo only available for US consumers.
** Apple, Apple Pay, and Apple Wallet are registered trademarks of Apple Inc.

Permalink | 23rd August 2023 09:18


CubeCart 6.5 Released - Featuring Search-as-you-type (Powered by Elasticsearch)

We are very excited to announce the release of CubeCart 6.5. 

After huge demand for improved search this version features a totally new search engine powered by Elasticsearch. This will allow your customers to locate products faster and with more relevance. An interactive search-as-you-type tool allows for immediate product access (see video below).

Elasticsearch is included as standard with official CubeCart Hosting and our staff will make any code changes necessary for it to work with custom or 3rd party skins. Alternatively please contact your hosting company to check for Elasticsearch availability. For more information talk to us at [email protected].

Download: CubeCart-6.5.0.zip
Download: CubeCart-6.5.1.zip

Developer Notes: 
For those using a custom or 3rd party skins Elasticsearch will need coding. The following attached document picks out the HTML, CSS and JS changes required. Please note that we can offer this service under our technical support services and to new and existing CubeCart hosted merchants.
6.5 - Elasticsearch Skin Changes.html

 

Permalink | 28th March 2023 14:17

  • BarclayCard Partner Logo
  • Chronopay Logo
  • eWay Logo
  • Nochex Logo
  • Skrill Logo
  • PayPoint.net Logo
  • Payment Sense Logo
  • PayPal Partner Logo
  • PayVector Logo
  • SagePay Partner Logo
  • Total Web Solutions Logo
  • Worlday Logo