VYPR

Quick CMS

by Quick CMS

CVEs (5)

  • CVE-2021-47981MedMay 16, 2026
    risk 0.35cvss 5.4epss 0.00

    Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to inject malicious scripts by submitting XSS payloads through the sDescription parameter. Attackers can craft CSRF forms targeting the admin.php?p=sliders-form…

  • CVE-2026-33385MedJul 29, 2026
    risk 0.00cvss epss 0.00

    A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a high-privileged user into multiple fields in administration panel allows for Blind SQL Injection attacks. The vendor states that this administration panel…

  • CVE-2026-63303MedJul 28, 2026
    risk 0.00cvss epss 0.00

    A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolving and serving the requested file. An authenticated attacker with admin privileges can use this…

  • CVE-2026-63302MedJul 28, 2026
    risk 0.00cvss epss 0.00

    Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated attacker with admin privileges can include arbitrary files located within the application's directory structure via a crafted HTTP request. Successful…

  • CVE-2026-63301HigJul 28, 2026
    risk 0.00cvss epss 0.00

    In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; however, the underlying language-deletion API endpoint does not enforce an equivalent server-side authorization check. As a result,…