Q CMS
Products
2- 15 CVEs
- 1 CVE
Recent CVEs
16| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-67854 | Cri | 0.64 | 9.8 | 0.01 | Aug 17, 2026 | SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code | ||
| CVE-2018-14978 | Hig | 0.57 | 8.8 | 0.00 | Aug 6, 2018 | An issue was discovered in QCMS 3.0.1. CSRF exists via the backend/user/admin/add.html URI. | ||
| CVE-2020-10578 | Hig | 0.49 | 7.5 | 0.01 | Mar 14, 2020 | An arbitrary file read vulnerability exists in system/controller/backend/template.php in QCMS v3.0.1. | ||
| CVE-2026-94110 | Hig | 0.47 | 7.3 | 0.00 | Sep 21, 2026 | A security vulnerability has been detected in QCMS up to 6.0.6. This issue affects the function self_Tmp in the library Lib/Config/Controllers.php of the component Content Detail Page. Such manipulation of the argument ID leads to sql injection. The attack may be performed from… | ||
| CVE-2025-50233 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2025 | A vulnerability in QCMS version 6.0.5 allows authenticated users to read arbitrary files from the server due to insufficient validation of the "Name" parameter in the backend template editor. By manipulating the parameter, attackers can perform directory traversal and access… | ||
| CVE-2018-14977 | Med | 0.40 | 6.1 | 0.01 | Aug 6, 2018 | An issue was discovered in QCMS 3.0.1. upload/System/Controller/guest.php has XSS, as demonstrated by the name parameter, a different vulnerability than CVE-2018-8070. | ||
| CVE-2018-8070 | Med | 0.35 | 5.4 | 0.01 | Mar 12, 2018 | QCMS version 3.0 has XSS via the title parameter to the /guest/index.html URI. | ||
| CVE-2018-8069 | Med | 0.35 | 5.4 | 0.01 | Mar 12, 2018 | QCMS version 3.0 has XSS via the webname parameter to the /backend/system.html URI. | ||
| CVE-2018-14976 | Med | 0.31 | 4.8 | 0.01 | Aug 6, 2018 | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/category.php has XSS. | ||
| CVE-2018-14975 | Med | 0.31 | 4.8 | 0.01 | Aug 6, 2018 | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/album.php has XSS. | ||
| CVE-2018-14974 | Med | 0.31 | 4.8 | 0.01 | Aug 6, 2018 | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/news.php has XSS. | ||
| CVE-2018-14973 | Med | 0.31 | 4.8 | 0.01 | Aug 6, 2018 | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/product.php has XSS. | ||
| CVE-2018-14972 | Med | 0.31 | 4.8 | 0.01 | Aug 6, 2018 | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/down.php has XSS. | ||
| CVE-2018-14971 | Med | 0.31 | 4.8 | 0.01 | Aug 6, 2018 | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/user.php has XSS. | ||
| CVE-2018-14970 | Med | 0.31 | 4.8 | 0.01 | Aug 6, 2018 | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/slideshow.php has XSS. | ||
| CVE-2018-14969 | Med | 0.31 | 4.8 | 0.01 | Aug 6, 2018 | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/system.php has XSS. |
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code
- risk 0.57cvss 8.8epss 0.00
An issue was discovered in QCMS 3.0.1. CSRF exists via the backend/user/admin/add.html URI.
- risk 0.49cvss 7.5epss 0.01
An arbitrary file read vulnerability exists in system/controller/backend/template.php in QCMS v3.0.1.
- risk 0.47cvss 7.3epss 0.00
A security vulnerability has been detected in QCMS up to 6.0.6. This issue affects the function self_Tmp in the library Lib/Config/Controllers.php of the component Content Detail Page. Such manipulation of the argument ID leads to sql injection. The attack may be performed from…
- risk 0.42cvss 6.5epss 0.00
A vulnerability in QCMS version 6.0.5 allows authenticated users to read arbitrary files from the server due to insufficient validation of the "Name" parameter in the backend template editor. By manipulating the parameter, attackers can perform directory traversal and access…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in QCMS 3.0.1. upload/System/Controller/guest.php has XSS, as demonstrated by the name parameter, a different vulnerability than CVE-2018-8070.
- risk 0.35cvss 5.4epss 0.01
QCMS version 3.0 has XSS via the title parameter to the /guest/index.html URI.
- risk 0.35cvss 5.4epss 0.01
QCMS version 3.0 has XSS via the webname parameter to the /backend/system.html URI.
- risk 0.31cvss 4.8epss 0.01
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/category.php has XSS.
- risk 0.31cvss 4.8epss 0.01
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/album.php has XSS.
- risk 0.31cvss 4.8epss 0.01
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/news.php has XSS.
- risk 0.31cvss 4.8epss 0.01
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/product.php has XSS.
- risk 0.31cvss 4.8epss 0.01
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/down.php has XSS.
- risk 0.31cvss 4.8epss 0.01
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/user.php has XSS.
- risk 0.31cvss 4.8epss 0.01
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/slideshow.php has XSS.
- risk 0.31cvss 4.8epss 0.01
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/system.php has XSS.