Opensolution Opensolution

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Opensolution product.

RSS Feeds for Opensolution security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Opensolution products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Opensolution Sorted by Most Security Vulnerabilities since 2018

Opensolution Quickcms16 vulnerabilities

Opensolution Quick Cms9 vulnerabilities

Opensolution Quick Cart2 vulnerabilities

Opensolution Quick Cms Ext2 vulnerabilities

By the Year

In 2026 there have been 14 vulnerabilities in Opensolution with an average score of 5.3 out of ten. Last year, in 2025 Opensolution had 7 security vulnerabilities published. That is, 7 more vulnerabilities have already been reported in 2026 as compared to last year.




Year Vulnerabilities Average Score
2026 14 5.25
2025 7 0.00
2024 1 0.00
2023 5 6.04

It may take a day or so for new Opensolution vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Opensolution Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-33385 Jul 29, 2026
Quick.CMS 6.8 Admin Panel Blind SQL Injection A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a high-privileged user into multiple fields in administration panel allows for Blind SQL Injection attacks. The vendor states that this administration panel already allows for significant modification capabilities. The SQL injection vulnerability primarily enables bypassing front-end validation controls and potential database destruction. Given the trust model in which this application is designed to be administered, remediation of this issue was not deemed necessary by the vendor. This vulnerability has been found in version 6.8, but other versions might also be vulnerable.
Quick Cms
CVE-2026-41874 Jul 28, 2026
Quick.Cart plaintext admin credentials stored in config file (v6.7+) Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with access to the server file system to retrieve authentication details, potentially leading to privilege escalation. The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary. Only version 6.7 was tested but all versions should be considered as vulnerable.
Quick Cart
CVE-2026-63303 Jul 28, 2026
Quick.CMS Path Traversal via unnormalized '../' in URI A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolving and serving the requested file. An authenticated attacker with admin privileges can use this vulnerability to read contents of files located in the sibling directory of the webroot via a crafted HTTP request containing ../ sequences in the URI. The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.
Quickcms
CVE-2026-63302 Jul 28, 2026
Quick.CMS LFI in admin.php: Remote Path Disclosure via p Param Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated attacker with admin privileges can include arbitrary files located within the application's directory structure via a crafted HTTP request. Successful exploitation allows disclosure of the server's directory structure and absolute file paths (path disclosure). The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.
Quickcms
CVE-2026-63301 Jul 28, 2026
Quick.CMS Admin API Bypass Enables Primary Language Deletion DoS (CSRF) In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; however, the underlying language-deletion API endpoint does not enforce an equivalent server-side authorization check. As a result, an authenticated administrator can bypass the UI-level restriction and delete the primary language by sending a direct HTTP request to the API endpoint. Successful deletion of the primary language results in a Denial of Service (DoS) of application. Critically, when combined with a separate Cross-Site Request Forgery (CSRF) vulnerability (CVE-2026-1468) an unauthenticated remote attacker can craft a malicious link, which if visited by an authenticated administrator, will trigger the DoS condition without direct access to the application The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.
Quickcms
CVE-2026-11860 Jun 15, 2026
Quick.CMS 6.8 RCE via deserialization of untrusted payload over HTTP Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. This allows attackers to tamper with serialized payloads in transit and inject malicious objects. Because deserialization is performed without proper validation or class restrictions, crafted payloads can trigger dangerous magic methods (e.g., __wakeup() and __destruct()) and leverage gadget chains, resulting in arbitrary code execution. Exploitation is triggered automatically when an administrator accesses the admin panel. When successfully exploited, this vulnerability allows attackers to execute arbitrary code on the server via manipulated serialized data transmitted over an unprotected channel. This issue was mitigated by limiting the communication to HTTPS in a patch for version 6.8 published on 14.05.2026, deployments without this patch remain vulnerable.
Quickcms
CVE-2026-33386 May 29, 2026
CVE-2026-33386 QuickCMS <6.8 XSS via insecure HTTP pluginfetch - MITM QuickCMS is vulnerable to Cross-Site Scripting (XSS) through its insecure HTTP-based pluginfetching mechanism. A malicious attacker can perform a ManintheMiddle (MITM) attack by impersonating the opensolution.org server and serving arbitrary HTML or JavaScript at the plugin list endpoint. When a user accesses the plugin page, the malicious content is automatically fetched, rendered, and executed. This issue was fixed in a patch to version 6.8 published on 15.05.2026, deployments without this patch are still vulnerable.
Quickcms
CVE-2026-33384 May 29, 2026
QuickCMS 6.X Session ID Fixation before Authentication (CVE-2026-33384) QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. This issue was fixed in a patch to version 6.8 published on 15.05.2026, deployments without this patch are still vulnerable.
Quickcms
CVE-2021-47981 May 16, 2026
XSS in Quick.CMS 6.7 Sliders Form (sDescription) allows CSRF Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to inject malicious scripts by submitting XSS payloads through the sDescription parameter. Attackers can craft CSRF forms targeting the admin.php?p=sliders-form endpoint to execute arbitrary JavaScript in victim browsers when the form is submitted.
Quick Cms
Quick Cms Ext
CVE-2026-1468 Mar 06, 2026
QuickCMS 6.8: CSRF Vulnerability Across Endpoints QuickCMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. An attacker can craft special website, which when visited by the victim, will automatically send a POST request with victim's privileges. This software does not implement any protection against this type of attack. All forms available in this software are potentially vulnerable. This issue was fixed in a patch to version 6.8 published on 14.05.2026, deployments without this patch are still vulnerable
Quickcms
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.