Opensolution

Quick.Cms

22 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 23.10.2025 09:37:33
  • Zuletzt bearbeitet 17.11.2025 16:01:39

QuickCMS is vulnerable to multiple Stored XSS in page editor functionality (pages-form). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By default adm...

  • EPSS 0.25%
  • Veröffentlicht 28.08.2025 11:15:33
  • Zuletzt bearbeitet 08.09.2025 17:15:37

QuickCMS is vulnerable to Reflected XSS via sLangEdit parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. The vendor w...

  • EPSS 0.2%
  • Veröffentlicht 28.08.2025 11:15:32
  • Zuletzt bearbeitet 08.09.2025 17:15:28

QuickCMS is vulnerable to Stored XSS via aDirFilesDescriptions parameter in files editor functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page....

  • EPSS 0.2%
  • Veröffentlicht 28.08.2025 11:15:32
  • Zuletzt bearbeitet 08.09.2025 16:56:05

QuickCMS is vulnerable to Stored XSS via sDescriptionMeta parameter in page editor SEO functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. B...

  • EPSS 0.13%
  • Veröffentlicht 28.08.2025 11:15:32
  • Zuletzt bearbeitet 08.09.2025 16:56:12

QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser history to obtain the necessary credentials to log in as the user. The vendor was notified early about this vulnerability, but didn't...

  • EPSS 0.15%
  • Veröffentlicht 28.08.2025 11:15:32
  • Zuletzt bearbeitet 08.09.2025 16:56:22

QuickCMS is vulnerable to Cross-Site Request Forgery in page deletion functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request deleting an article. The vendor was notified e...

  • EPSS 0.25%
  • Veröffentlicht 28.08.2025 11:15:30
  • Zuletzt bearbeitet 08.09.2025 17:06:51

QuickCMS is vulnerable to Reflected XSS via sSort parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. The vendor was n...

  • EPSS 0.13%
  • Veröffentlicht 20.08.2025 12:53:09
  • Zuletzt bearbeitet 08.09.2025 17:08:58

QuickCMS is vulnerable to Cross-Site Request Forgery in article creation functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request creating a malicious article with content de...

  • EPSS 0.19%
  • Veröffentlicht 20.08.2025 12:52:47
  • Zuletzt bearbeitet 08.09.2025 17:10:23

QuickCMS is vulnerable to Stored XSS in sTitle parameter in page editor functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. Regular admin us...

Exploit
  • EPSS 10.46%
  • Veröffentlicht 28.01.2021 20:15:12
  • Zuletzt bearbeitet 21.11.2024 05:28:00

OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab.