Opensolution
Opensolution Quick.cms: vulnerabilidades y CVE
Opensolution Quick.cms tiene 20 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE20
Últimos 12 meses8
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-33385 | Media (5.1) | 0.41% | — | 29 jul 2026 | A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a high-privileged user into multiple fields in administration panel allows for Blind SQL Injection… |
| CVE-2026-63303 | Media (5.1) | 0.57% | — | 28 jul 2026 | A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolving and serving the requested file. An… |
| CVE-2026-63302 | Media (5.1) | 0.53% | — | 28 jul 2026 | Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated attacker with admin privileges can include arbitrary files located within the application's directory… |
| CVE-2021-47981 | Media (5.1) | 0.18% | — | 16 may 2026 | Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to inject malicious scripts by submitting XSS payloads through the sDescription parameter. Attackers… |
| CVE-2025-9982 | Media (6.9) | 0.27% | — | 14 nov 2025 | A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file and stored in plaintext. This flaw allows attackers with access to the source code or the server… |
| CVE-2025-10018 | Media (4.8) | 0.18% | — | 14 nov 2025 | QuickCMS is vulnerable to multiple Stored XSS in language editor functionality (languages). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed on… |
| CVE-2025-9981 | Media (4.8) | 0.19% | — | 23 oct 2025 | QuickCMS is vulnerable to multiple Stored XSS in slider editor functionality (sliders-form). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed on… |
| CVE-2025-9980 | Media (4.8) | 0.19% | — | 23 oct 2025 | QuickCMS is vulnerable to multiple Stored XSS in page editor functionality (pages-form). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when… |
| CVE-2025-55175 | Media (5.1) | 0.25% | — | 28 ago 2025 | QuickCMS is vulnerable to Reflected XSS via sLangEdit parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the… |
| CVE-2025-54544 | Media (5.3) | 0.19% | — | 28 ago 2025 | QuickCMS is vulnerable to Stored XSS via aDirFilesDescriptions parameter in files editor functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be… |
| CVE-2025-54543 | Media (5.3) | 0.19% | — | 28 ago 2025 | QuickCMS is vulnerable to Stored XSS via sDescriptionMeta parameter in page editor SEO functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be… |
| CVE-2025-54542 | Media (6.9) | 0.14% | — | 28 ago 2025 | QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser history to obtain the necessary credentials to log in as the user. The vendor was notified early about… |
| CVE-2025-54541 | Media (6.9) | 0.15% | — | 28 ago 2025 | QuickCMS is vulnerable to Cross-Site Request Forgery in page deletion functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request deleting an… |
| CVE-2025-54540 | Media (5.1) | 0.25% | — | 28 ago 2025 | QuickCMS is vulnerable to Reflected XSS via sSort parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the… |
| CVE-2025-54174 | Media (5.1) | 0.13% | — | 20 ago 2025 | QuickCMS is vulnerable to Cross-Site Request Forgery in article creation functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request creating a… |
| CVE-2025-54172 | Media (4.8) | 0.19% | — | 20 ago 2025 | QuickCMS is vulnerable to Stored XSS in sTitle parameter in page editor functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when… |
| CVE-2024-11992 | Crítica (9.1) | 0.82% | — | 29 nov 2024 | Absolute path traversal vulnerability in Quick.CMS, version 6.7, the exploitation of which could allow remote users to bypass the intended restrictions and download any file if it has the appropriate permissions outside… |
| CVE-2020-35754 | Alta (7.2) | 10% | — | 28 ene 2021 | OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab. |
| CVE-2012-3833 | Media (4.3) | 1.2% | — | 3 jul 2012 | Cross-site scripting (XSS) vulnerability in the default index page in admin/ in Quick.CMS 4.0 allows remote attackers to inject arbitrary web script or HTML via the p parameter. |
| CVE-2009-4121 | Media (6.8) | 0.65% | — | 1 dic 2009 | Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.CMS 2.4 and Quick.CMS.Lite 2.4 allow remote attackers to hijack the authentication of the administrator for requests that (1) delete web pages via a… |