Opensolution

Quick.Cms

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 28.08.2025 11:15:32
  • Zuletzt bearbeitet 08.09.2025 16:56:12

QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser history to obtain the necessary credentials to log in as the user. The vendor was notified early about this vulnerability, but didn't...

  • EPSS 0.14%
  • Veröffentlicht 28.08.2025 11:15:32
  • Zuletzt bearbeitet 08.09.2025 16:56:22

QuickCMS is vulnerable to Cross-Site Request Forgery in page deletion functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request deleting an article. The vendor was notified e...

  • EPSS 0.24%
  • Veröffentlicht 28.08.2025 11:15:30
  • Zuletzt bearbeitet 08.09.2025 17:06:51

QuickCMS is vulnerable to Reflected XSS via sSort parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. The vendor was n...

  • EPSS 0.12%
  • Veröffentlicht 20.08.2025 12:53:09
  • Zuletzt bearbeitet 08.09.2025 17:08:58

QuickCMS is vulnerable to Cross-Site Request Forgery in article creation functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request creating a malicious article with content de...

  • EPSS 0.18%
  • Veröffentlicht 20.08.2025 12:52:47
  • Zuletzt bearbeitet 08.09.2025 17:10:23

QuickCMS is vulnerable to Stored XSS in sTitle parameter in page editor functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. Regular admin us...

Exploit
  • EPSS 10.46%
  • Veröffentlicht 28.01.2021 20:15:12
  • Zuletzt bearbeitet 21.11.2024 05:28:00

OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab.

Exploit
  • EPSS 1.2%
  • Veröffentlicht 03.07.2012 22:55:02
  • Zuletzt bearbeitet 16.06.2026 23:43:58

Cross-site scripting (XSS) vulnerability in the default index page in admin/ in Quick.CMS 4.0 allows remote attackers to inject arbitrary web script or HTML via the p parameter.

Exploit
  • EPSS 0.65%
  • Veröffentlicht 01.12.2009 02:30:00
  • Zuletzt bearbeitet 16.06.2026 23:13:04

Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.CMS 2.4 and Quick.CMS.Lite 2.4 allow remote attackers to hijack the authentication of the administrator for requests that (1) delete web pages via a p-delete action to admin.php, and...