CVE-2026-33386
- EPSS 0.19%
- Veröffentlicht 29.05.2026 16:16:25
- Zuletzt bearbeitet 29.05.2026 16:29:11
QuickCMS is vulnerable to Cross-Site Scripting (XSS) through its insecure HTTP-based plugin‑fetching mechanism. A malicious attacker can perform a Man‑in‑the‑Middle (MITM) attack by impersonating the opensolution.org server and serving arbitrary HTML...
CVE-2026-33384
- EPSS 0.15%
- Veröffentlicht 29.05.2026 16:16:25
- Zuletzt bearbeitet 29.05.2026 16:29:11
QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated sess...
CVE-2026-1468
- EPSS 0.22%
- Veröffentlicht 06.03.2026 11:04:07
- Zuletzt bearbeitet 27.04.2026 19:22:08
QuickCMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. An attacker can craft special website, which when visited by the victim, will automatically send a POST request with victim's privileges. This software does not implement...
CVE-2024-58308
- EPSS 0.61%
- Veröffentlicht 11.12.2025 21:42:09
- Zuletzt bearbeitet 31.12.2025 18:30:13
Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating the login form. Attackers can inject specific SQL payloads like ' or '1'='1 to gain unauthorized administrative ...
CVE-2025-12465
- EPSS 0.23%
- Veröffentlicht 02.12.2025 12:15:22
- Zuletzt bearbeitet 15.04.2026 00:35:42
A Blind SQL injection vulnerability has been identified in QuickCMS. Improper neutralization of input provided by a high-privileged user into aFilesDelete allows for Blind SQL Injection attacks. The vendor was notified early about this vulnerability...
CVE-2025-10018
- EPSS 0.15%
- Veröffentlicht 14.11.2025 13:22:19
- Zuletzt bearbeitet 17.11.2025 19:26:29
QuickCMS is vulnerable to multiple Stored XSS in language editor functionality (languages). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed on every page. By default admin user i...
CVE-2025-9982
- EPSS 0.24%
- Veröffentlicht 14.11.2025 13:22:16
- Zuletzt bearbeitet 17.11.2025 19:28:12
A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file and stored in plaintext. This flaw allows attackers with access to the source code or the server file system to retrieve authentica...
CVE-2025-9981
- EPSS 0.18%
- Veröffentlicht 23.10.2025 09:37:44
- Zuletzt bearbeitet 17.11.2025 15:57:33
QuickCMS is vulnerable to multiple Stored XSS in slider editor functionality (sliders-form). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed on every page. By default admin user ...
CVE-2025-9980
- EPSS 0.18%
- Veröffentlicht 23.10.2025 09:37:33
- Zuletzt bearbeitet 17.11.2025 16:01:39
QuickCMS is vulnerable to multiple Stored XSS in page editor functionality (pages-form). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By default adm...
CVE-2025-55175
- EPSS 0.24%
- Veröffentlicht 28.08.2025 11:15:33
- Zuletzt bearbeitet 08.09.2025 17:15:37
QuickCMS is vulnerable to Reflected XSS via sLangEdit parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. The vendor w...