VYPR
Vendor

Q CMS

Products
2
CVEs
16
Across products
16
Status
Private

Products

2

Recent CVEs

16
  • CVE-2026-67854CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code

  • CVE-2018-14978HigAug 6, 2018
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in QCMS 3.0.1. CSRF exists via the backend/user/admin/add.html URI.

  • CVE-2020-10578HigMar 14, 2020
    risk 0.49cvss 7.5epss 0.01

    An arbitrary file read vulnerability exists in system/controller/backend/template.php in QCMS v3.0.1.

  • CVE-2026-94110HigSep 21, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in QCMS up to 6.0.6. This issue affects the function self_Tmp in the library Lib/Config/Controllers.php of the component Content Detail Page. Such manipulation of the argument ID leads to sql injection. The attack may be performed from…

  • CVE-2025-50233MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in QCMS version 6.0.5 allows authenticated users to read arbitrary files from the server due to insufficient validation of the "Name" parameter in the backend template editor. By manipulating the parameter, attackers can perform directory traversal and access…

  • CVE-2018-14977MedAug 6, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in QCMS 3.0.1. upload/System/Controller/guest.php has XSS, as demonstrated by the name parameter, a different vulnerability than CVE-2018-8070.

  • CVE-2018-8070MedMar 12, 2018
    risk 0.35cvss 5.4epss 0.01

    QCMS version 3.0 has XSS via the title parameter to the /guest/index.html URI.

  • CVE-2018-8069MedMar 12, 2018
    risk 0.35cvss 5.4epss 0.01

    QCMS version 3.0 has XSS via the webname parameter to the /backend/system.html URI.

  • CVE-2018-14976MedAug 6, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/category.php has XSS.

  • CVE-2018-14975MedAug 6, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/album.php has XSS.

  • CVE-2018-14974MedAug 6, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/news.php has XSS.

  • CVE-2018-14973MedAug 6, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/product.php has XSS.

  • CVE-2018-14972MedAug 6, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/down.php has XSS.

  • CVE-2018-14971MedAug 6, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/user.php has XSS.

  • CVE-2018-14970MedAug 6, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/slideshow.php has XSS.

  • CVE-2018-14969MedAug 6, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/system.php has XSS.

VYPR — Vulnerability Intelligence