Quick Cms Opensolution Quick Cms

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Opensolution Quick Cms.

By the Year

In 2026 there have been 2 vulnerabilities in Opensolution Quick Cms with an average score of 5.4 out of ten. Last year, in 2025 Quick Cms had 1 security vulnerability published. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.




Year Vulnerabilities Average Score
2026 2 5.40
2025 1 0.00
2024 1 0.00
2023 5 6.04

It may take a day or so for new Quick Cms vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Opensolution Quick Cms Security Vulnerabilities

Quick.CMS 6.8 Admin Panel Blind SQL Injection
CVE-2026-33385 - July 29, 2026

A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a high-privileged user into multiple fields in administration panel allows for Blind SQL Injection attacks. The vendor states that this administration panel already allows for significant modification capabilities. The SQL injection vulnerability primarily enables bypassing front-end validation controls and potential database destruction. Given the trust model in which this application is designed to be administered, remediation of this issue was not deemed necessary by the vendor. This vulnerability has been found in version 6.8, but other versions might also be vulnerable.

SQL Injection

XSS in Quick.CMS 6.7 Sliders Form (sDescription) allows CSRF
CVE-2021-47981 5.4 - Medium - May 16, 2026

Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to inject malicious scripts by submitting XSS payloads through the sDescription parameter. Attackers can craft CSRF forms targeting the admin.php?p=sliders-form endpoint to execute arbitrary JavaScript in victim browsers when the form is submitted.

XSS

Quick.CMS 6.7 SQLi via Login Form Unauthorized Admin Access
CVE-2024-58308 - December 11, 2025

Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating the login form. Attackers can inject specific SQL payloads like ' or '1'='1 to gain unauthorized administrative access to the system.

SQL Injection

Quick.CMS 6.7: Absolute Path Traversal Vulnerability in admin.php
CVE-2024-11992 - November 29, 2024

Absolute path traversal vulnerability in Quick.CMS, version 6.7, the exploitation of which could allow remote users to bypass the intended restrictions and download any file if it has the appropriate permissions outside of documentroot configured on the server via the aDirFiles%5B0%5D parameter in the admin.php page. This vulnerability allows an attacker to delete files stored on the server due to a lack of proper verification of user-supplied input.

XSS in opensolution Quick CMS 6.7 Languages Menu Backend Dashboard
CVE-2023-43346 5.4 - Medium - October 20, 2023

Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Backend - Dashboard parameter in the Languages Menu component.

XSS

Quick CMS v6.7 XSS in Pages Menu via Content-Name param
CVE-2023-43345 8.6 - High - October 19, 2023

Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Content - Name parameter in the Pages Menu component.

XSS

XSS in OpenSolution QuickCMS 6.7 Pages Menu via SEO Meta
CVE-2023-43344 5.4 - Medium - October 19, 2023

Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the SEO - Meta description parameter in the Pages Menu component.

XSS

XSS in opensolution Quick CMS 6.7 Languages Menu
CVE-2023-43342 5.4 - Medium - October 19, 2023

Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Languages Menu component.

XSS

OpenSolution QuickCMS 6.7 XSS via PagesMenu FilesDesc Param
CVE-2023-43343 5.4 - Medium - October 05, 2023

Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Files - Description parameter in the Pages Menu component.

XSS

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Opensolution Quick Cms or by Opensolution? Click the Watch button to subscribe.

subscribe