Opensolution

Quick Cms

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.32%
  • Veröffentlicht 11.12.2025 21:42:09
  • Zuletzt bearbeitet 31.12.2025 18:30:13

Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating the login form. Attackers can inject specific SQL payloads like ' or '1'='1 to gain unauthorized administrative ...

  • EPSS 0.04%
  • Veröffentlicht 02.12.2025 12:15:22
  • Zuletzt bearbeitet 02.12.2025 17:16:29

A Blind SQL injection vulnerability has been identified in QuickCMS. Improper neutralization of input provided by a high-privileged user into aFilesDelete allows for Blind SQL Injection attacks. The vendor was notified early about this vulnerability...

  • EPSS 0.04%
  • Veröffentlicht 14.11.2025 13:22:19
  • Zuletzt bearbeitet 17.11.2025 19:26:29

QuickCMS is vulnerable to multiple Stored XSS in language editor functionality (languages). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed on every page. By default admin user i...

  • EPSS 0.06%
  • Veröffentlicht 14.11.2025 13:22:16
  • Zuletzt bearbeitet 17.11.2025 19:28:12

A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file and stored in plaintext. This flaw allows attackers with access to the source code or the server file system to retrieve authentica...

  • EPSS 0.05%
  • Veröffentlicht 23.10.2025 09:37:44
  • Zuletzt bearbeitet 17.11.2025 15:57:33

QuickCMS is vulnerable to multiple Stored XSS in slider editor functionality (sliders-form). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed on every page. By default admin user ...

  • EPSS 0.05%
  • Veröffentlicht 23.10.2025 09:37:33
  • Zuletzt bearbeitet 17.11.2025 16:01:39

QuickCMS is vulnerable to multiple Stored XSS in page editor functionality (pages-form). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By default adm...

  • EPSS 0.03%
  • Veröffentlicht 28.08.2025 11:15:33
  • Zuletzt bearbeitet 08.09.2025 17:15:37

QuickCMS is vulnerable to Reflected XSS via sLangEdit parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. The vendor w...

  • EPSS 0.02%
  • Veröffentlicht 28.08.2025 11:15:32
  • Zuletzt bearbeitet 08.09.2025 16:56:05

QuickCMS is vulnerable to Stored XSS via sDescriptionMeta parameter in page editor SEO functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. B...

  • EPSS 0.02%
  • Veröffentlicht 28.08.2025 11:15:32
  • Zuletzt bearbeitet 08.09.2025 17:15:28

QuickCMS is vulnerable to Stored XSS via aDirFilesDescriptions parameter in files editor functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page....

  • EPSS 0.02%
  • Veröffentlicht 28.08.2025 11:15:32
  • Zuletzt bearbeitet 08.09.2025 16:56:12

QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser history to obtain the necessary credentials to log in as the user. The vendor was notified early about this vulnerability, but didn't...