Vulnerability index

Browse CVEs

19 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-23796 Quick.Cart allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This… Quick.cart Mitigation only Fix from $2,3002026-02-05 HIGH 7.2 CVE-2025-67684 Quick.Cart is vulnerable to Local File Inclusion and Path Traversal issues in the theme selection mechanism. Quick.Cart allows a privileged user to u… Quick.cart Mitigation only Fix from $1,9502026-01-22 MEDIUM 6.1 CVE-2025-67683 Quick.Cart is vulnerable to reflected XSS via the sSort parameter. An attacker can craft a malicious URL which, when opened, results in arbitrary Jav… Quick.cart Mitigation only Fix from $1,6002026-01-22 CRITICAL 9.8 CVE-2024-58308 Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating the login f… Quick Cms Mitigation only Fix from $2,3002025-12-11 HIGH 7.5 CVE-2025-9982 A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file and stored in plaintext. This … Quick.cms Mitigation only Fix from $1,9502025-11-14 MEDIUM 6.1 CVE-2025-55175 QuickCMS is vulnerable to Reflected XSS via sLangEdit parameter in admin's panel functionality. A malicious attacker can craft a specially crafted UR… Quick.cms Mitigation only Fix from $1,6002025-08-28 MEDIUM 5.5 CVE-2025-54542 QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser history to obtain the necessary c… Quick.cms Mitigation only Fix from $1,6002025-08-28 MEDIUM 6.1 CVE-2025-54540 QuickCMS is vulnerable to Reflected XSS via sSort parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL th… Quick.cms Mitigation only Fix from $1,6002025-08-28 MEDIUM 6.1 CVE-2025-54175 QuickCMS.EXT is vulnerable to Reflected XSS in sFileName parameter in thumbnail viewer functionality.  An attacker can craft a malicious URL that res… Quick.cms.ext Mitigation only Fix from $1,6002025-08-20 MEDIUM 5.4 CVE-2023-43346 Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to th… Quick Cms No fix yet Fix from $1,6002023-10-20 HIGH 8.6 CVE-2023-43345 Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to th… Quick Cms No fix yet Fix from $1,9502023-10-19 MEDIUM 5.4 CVE-2023-43342 Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to th… Quick Cms No fix yet Fix from $1,6002023-10-19 MEDIUM 5.4 CVE-2023-43344 Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to th… Quick Cms No fix yet Fix from $1,6002023-10-19 MEDIUM 5.4 CVE-2023-43343 Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to th… Quick Cms No fix yet Fix from $1,6002023-10-05 MEDIUM 5.0 CVE-2012-6049 Open Solution Quick.Cart 5.0 allows remote attackers to obtain sensitive information via (1) a long string or (2) invalid characters in a cookie, whi… Quick.cart Mitigation only Fix from $1,6002012-11-27 MEDIUM 6.8 CVE-2009-4120 Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote attackers to hijack the authentication of the administrator… Quick.cart No fix yet Fix from $1,6002009-12-01 MEDIUM 6.8 CVE-2009-4121 Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.CMS 2.4 and Quick.CMS.Lite 2.4 allow remote attackers to hijack the authenticatio… Quick.cms No fix yet Fix from $1,6002009-12-01 HIGH 7.5 CVE-2009-1410 SQL injection vulnerability in index.php in Quick.Cms.Lite 0.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. Quick.cms.lite No fix yet Fix from $1,9502009-04-24 MEDIUM 5.0 CVE-2006-5834 Directory traversal vulnerability in general.php in OpenSolution Quick.Cms.Lite 0.3 allows remote attackers to include arbitrary files via a .. (dot … Quick.cms.lite No fix yet Fix from $1,6002006-11-10