Opensolution

Quick Cms

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 29.05.2026 16:16:25
  • Zuletzt bearbeitet 29.05.2026 16:29:11

QuickCMS is vulnerable to Cross-Site Scripting (XSS) through its insecure HTTP-based plugin‑fetching mechanism. A malicious attacker can perform a Man‑in‑the‑Middle (MITM) attack by impersonating the opensolution.org server and serving arbitrary HTML...

  • EPSS 0.15%
  • Veröffentlicht 29.05.2026 16:16:25
  • Zuletzt bearbeitet 29.05.2026 16:29:11

QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated sess...

  • EPSS 0.22%
  • Veröffentlicht 06.03.2026 11:04:07
  • Zuletzt bearbeitet 27.04.2026 19:22:08

QuickCMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. An attacker can craft special website, which when visited by the victim, will automatically send a POST request with victim's privileges. This software does not implement...

Exploit
  • EPSS 0.61%
  • Veröffentlicht 11.12.2025 21:42:09
  • Zuletzt bearbeitet 31.12.2025 18:30:13

Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating the login form. Attackers can inject specific SQL payloads like ' or '1'='1 to gain unauthorized administrative ...

  • EPSS 0.23%
  • Veröffentlicht 02.12.2025 12:15:22
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A Blind SQL injection vulnerability has been identified in QuickCMS. Improper neutralization of input provided by a high-privileged user into aFilesDelete allows for Blind SQL Injection attacks. The vendor was notified early about this vulnerability...

  • EPSS 0.15%
  • Veröffentlicht 14.11.2025 13:22:19
  • Zuletzt bearbeitet 17.11.2025 19:26:29

QuickCMS is vulnerable to multiple Stored XSS in language editor functionality (languages). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed on every page. By default admin user i...

  • EPSS 0.24%
  • Veröffentlicht 14.11.2025 13:22:16
  • Zuletzt bearbeitet 17.11.2025 19:28:12

A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file and stored in plaintext. This flaw allows attackers with access to the source code or the server file system to retrieve authentica...

  • EPSS 0.18%
  • Veröffentlicht 23.10.2025 09:37:44
  • Zuletzt bearbeitet 17.11.2025 15:57:33

QuickCMS is vulnerable to multiple Stored XSS in slider editor functionality (sliders-form). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed on every page. By default admin user ...

  • EPSS 0.18%
  • Veröffentlicht 23.10.2025 09:37:33
  • Zuletzt bearbeitet 17.11.2025 16:01:39

QuickCMS is vulnerable to multiple Stored XSS in page editor functionality (pages-form). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By default adm...

  • EPSS 0.24%
  • Veröffentlicht 28.08.2025 11:15:33
  • Zuletzt bearbeitet 08.09.2025 17:15:37

QuickCMS is vulnerable to Reflected XSS via sLangEdit parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. The vendor w...