Opensolution Quick Cart
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Opensolution Quick Cart.
By the Year
In 2026 there have been 2 vulnerabilities in Opensolution Quick Cart with an average score of 6.9 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2 | 6.90 |
It may take a day or so for new Quick Cart vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Opensolution Quick Cart Security Vulnerabilities
Quick.Cart 6.6-6.7 XSRF in admin config (referer bypass)
CVE-2026-41875
6.9 - Medium
- September 29, 2026
Quick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request that changes admin's login and password. This software does implement simple protection against this type of attack, but it is easily bypassed by manipulating the referer header. All forms available in this software are potentially vulnerable. This issue was fixed in a patch to version 6.7 published on 09.11.2026, deployments without this patch are still vulnerable
Session Riding
Quick.Cart plaintext admin credentials stored in config file (v6.7+)
CVE-2026-41874
- July 28, 2026
Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with access to the server file system to retrieve authentication details, potentially leading to privilege escalation. The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary. Only version 6.7 was tested but all versions should be considered as vulnerable.
Unprotected Storage of Credentials
SQL injection vulnerability in index.php for Quick.cart 0.3.0
CVE-2005-1588
- May 11, 2005
SQL injection vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to execute arbitrary SQL commands via the iCategory parameter. NOTE: the vendor has privately disputed this issue, saying that Quick.cart does not even use SQL and therefore can not be vulnerable to SQL injection
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Opensolution Quick Cart or by Opensolution? Click the Watch button to subscribe.