Opensolution

Quick.Cms

22 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 29.07.2026 13:18:08
  • Zuletzt bearbeitet 30.07.2026 19:09:20

A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a high-privileged user into multiple fields in administration panel allows for Blind SQL Injection attacks. The vendor states that thi...

  • EPSS 0.39%
  • Veröffentlicht 28.07.2026 10:43:05
  • Zuletzt bearbeitet 30.07.2026 16:29:42

A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolving and serving the requested file. An authenticated attacker with admi...

  • EPSS 0.31%
  • Veröffentlicht 28.07.2026 10:43:01
  • Zuletzt bearbeitet 30.07.2026 16:29:42

Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated attacker with admin privileges can include arbitrary files located within the application's directory structure via a crafted HTTP r...

  • EPSS 0.36%
  • Veröffentlicht 28.07.2026 10:42:56
  • Zuletzt bearbeitet 30.07.2026 16:29:42

In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; however, the underlying language-deletion API endpoint does not enforce an equivalent server-side auth...

  • EPSS 0.24%
  • Veröffentlicht 15.06.2026 09:57:11
  • Zuletzt bearbeitet 24.07.2026 19:10:00

Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. This allows attackers to tamper with serialized payloads in transit and inject malicious objects. Because deserialization is performe...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 16.05.2026 15:26:20
  • Zuletzt bearbeitet 18.05.2026 17:26:40

Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to inject malicious scripts by submitting XSS payloads through the sDescription parameter. Attackers can craft CSRF forms targeting th...

Exploit
  • EPSS 0.68%
  • Veröffentlicht 11.12.2025 21:42:09
  • Zuletzt bearbeitet 31.12.2025 18:30:13

Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating the login form. Attackers can inject specific SQL payloads like ' or '1'='1 to gain unauthorized administrative ...

  • EPSS 0.18%
  • Veröffentlicht 14.11.2025 13:22:19
  • Zuletzt bearbeitet 17.11.2025 19:26:29

QuickCMS is vulnerable to multiple Stored XSS in language editor functionality (languages). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed on every page. By default admin user i...

  • EPSS 0.27%
  • Veröffentlicht 14.11.2025 13:22:16
  • Zuletzt bearbeitet 17.11.2025 19:28:12

A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file and stored in plaintext. This flaw allows attackers with access to the source code or the server file system to retrieve authentica...

  • EPSS 0.18%
  • Veröffentlicht 23.10.2025 09:37:44
  • Zuletzt bearbeitet 17.11.2025 15:57:33

QuickCMS is vulnerable to multiple Stored XSS in slider editor functionality (sliders-form). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed on every page. By default admin user ...