CVE-2025-54542
- EPSS 0.12%
- Veröffentlicht 28.08.2025 11:15:32
- Zuletzt bearbeitet 08.09.2025 16:56:12
QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser history to obtain the necessary credentials to log in as the user. The vendor was notified early about this vulnerability, but didn't...
CVE-2025-54541
- EPSS 0.14%
- Veröffentlicht 28.08.2025 11:15:32
- Zuletzt bearbeitet 08.09.2025 16:56:22
QuickCMS is vulnerable to Cross-Site Request Forgery in page deletion functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request deleting an article. The vendor was notified e...
CVE-2025-54540
- EPSS 0.24%
- Veröffentlicht 28.08.2025 11:15:30
- Zuletzt bearbeitet 08.09.2025 17:06:51
QuickCMS is vulnerable to Reflected XSS via sSort parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. The vendor was n...
CVE-2025-54174
- EPSS 0.12%
- Veröffentlicht 20.08.2025 12:53:09
- Zuletzt bearbeitet 08.09.2025 17:08:58
QuickCMS is vulnerable to Cross-Site Request Forgery in article creation functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request creating a malicious article with content de...
CVE-2025-54172
- EPSS 0.18%
- Veröffentlicht 20.08.2025 12:52:47
- Zuletzt bearbeitet 08.09.2025 17:10:23
QuickCMS is vulnerable to Stored XSS in sTitle parameter in page editor functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. Regular admin us...
CVE-2020-35754
- EPSS 10.46%
- Veröffentlicht 28.01.2021 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:28:00
OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab.
CVE-2012-3833
- EPSS 1.2%
- Veröffentlicht 03.07.2012 22:55:02
- Zuletzt bearbeitet 16.06.2026 23:43:58
Cross-site scripting (XSS) vulnerability in the default index page in admin/ in Quick.CMS 4.0 allows remote attackers to inject arbitrary web script or HTML via the p parameter.
CVE-2009-4121
- EPSS 0.65%
- Veröffentlicht 01.12.2009 02:30:00
- Zuletzt bearbeitet 16.06.2026 23:13:04
Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.CMS 2.4 and Quick.CMS.Lite 2.4 allow remote attackers to hijack the authentication of the administrator for requests that (1) delete web pages via a p-delete action to admin.php, and...