Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Quick.cart CRITICAL 9.8
CVE-2026-23796

Quick.Cart allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This…

Mitigation only
Fix from $2,300 2026-02-05
Quick.cart HIGH 7.2
CVE-2025-67684

Quick.Cart is vulnerable to Local File Inclusion and Path Traversal issues in the theme selection mechanism. Quick.Cart allows a privileged user to u…

Mitigation only
Fix from $1,950 2026-01-22
Quick.cart MEDIUM 6.1
CVE-2025-67683

Quick.Cart is vulnerable to reflected XSS via the sSort parameter. An attacker can craft a malicious URL which, when opened, results in arbitrary Jav…

Mitigation only
Fix from $1,600 2026-01-22
Quick Cms CRITICAL 9.8
CVE-2024-58308

Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating the login f…

Mitigation only
Fix from $2,300 2025-12-11
Quick.cms HIGH 7.5
CVE-2025-9982

A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file and stored in plaintext. This …

Mitigation only
Fix from $1,950 2025-11-14
Quick.cms MEDIUM 6.1
CVE-2025-55175

QuickCMS is vulnerable to Reflected XSS via sLangEdit parameter in admin's panel functionality. A malicious attacker can craft a specially crafted UR…

Mitigation only
Fix from $1,600 2025-08-28
Quick.cms MEDIUM 5.5
CVE-2025-54542

QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser history to obtain the necessary c…

Mitigation only
Fix from $1,600 2025-08-28
Quick.cms MEDIUM 6.1
CVE-2025-54540

QuickCMS is vulnerable to Reflected XSS via sSort parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL th…

Mitigation only
Fix from $1,600 2025-08-28
Quick.cms.ext MEDIUM 6.1
CVE-2025-54175

QuickCMS.EXT is vulnerable to Reflected XSS in sFileName parameter in thumbnail viewer functionality.  An attacker can craft a malicious URL that res…

Mitigation only
Fix from $1,600 2025-08-20
Quick Cms MEDIUM 5.4
CVE-2023-43346

Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to th…

No fix yet
Fix from $1,600 2023-10-20
Quick Cms HIGH 8.6
CVE-2023-43345

Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to th…

No fix yet
Fix from $1,950 2023-10-19
Quick Cms MEDIUM 5.4
CVE-2023-43342

Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to th…

No fix yet
Fix from $1,600 2023-10-19
Quick Cms MEDIUM 5.4
CVE-2023-43344

Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to th…

No fix yet
Fix from $1,600 2023-10-19
Quick Cms MEDIUM 5.4
CVE-2023-43343

Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to th…

No fix yet
Fix from $1,600 2023-10-05
Quick.cart HIGH 7.2
CVE-2020-35754EPSS 10%

OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via …

Fix: 6.7+
Fix from $1,950 2021-01-28
Quick.cart MEDIUM 5.0
CVE-2012-6049

Open Solution Quick.Cart 5.0 allows remote attackers to obtain sensitive information via (1) a long string or (2) invalid characters in a cookie, whi…

Mitigation only
Fix from $1,600 2012-11-27
Quick.cart MEDIUM 6.8
CVE-2009-4120

Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote attackers to hijack the authentication of the administrator…

No fix yet
Fix from $1,600 2009-12-01
Quick.cms MEDIUM 6.8
CVE-2009-4121

Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.CMS 2.4 and Quick.CMS.Lite 2.4 allow remote attackers to hijack the authenticatio…

No fix yet
Fix from $1,600 2009-12-01
Quick.cms.lite HIGH 7.5
CVE-2009-1410

SQL injection vulnerability in index.php in Quick.Cms.Lite 0.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

No fix yet
Fix from $1,950 2009-04-24
Quick.cms.lite MEDIUM 5.0
CVE-2006-5834

Directory traversal vulnerability in general.php in OpenSolution Quick.Cms.Lite 0.3 allows remote attackers to include arbitrary files via a .. (dot …

No fix yet
Fix from $1,600 2006-11-10