CVE-2025-54540
- EPSS 0.03%
- Veröffentlicht 28.08.2025 11:15:30
- Zuletzt bearbeitet 08.09.2025 17:06:51
QuickCMS is vulnerable to Reflected XSS via sSort parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. The vendor was n...
CVE-2025-54174
- EPSS 0.02%
- Veröffentlicht 20.08.2025 12:53:09
- Zuletzt bearbeitet 08.09.2025 17:08:58
QuickCMS is vulnerable to Cross-Site Request Forgery in article creation functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request creating a malicious article with content de...
CVE-2025-54172
- EPSS 0.02%
- Veröffentlicht 20.08.2025 12:52:47
- Zuletzt bearbeitet 08.09.2025 17:10:23
QuickCMS is vulnerable to Stored XSS in sTitle parameter in page editor functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. Regular admin us...
CVE-2020-35754
- EPSS 14.46%
- Veröffentlicht 28.01.2021 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:28:00
OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab.
CVE-2012-3833
- EPSS 0.37%
- Veröffentlicht 03.07.2012 22:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the default index page in admin/ in Quick.CMS 4.0 allows remote attackers to inject arbitrary web script or HTML via the p parameter.
CVE-2009-4121
- EPSS 0.19%
- Veröffentlicht 01.12.2009 02:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.CMS 2.4 and Quick.CMS.Lite 2.4 allow remote attackers to hijack the authentication of the administrator for requests that (1) delete web pages via a p-delete action to admin.php, and...