quick.cms vulnerabilities
CVEs whose affected-version data names the quick.cms package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-9982High· 7.5A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file and stored in plaintext
A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file and stored in plaintext. This flaw allows attackers with access to the source code or the server file system to retrie…
▾ Twilightopensolution · quick.cmsEPSS 0.27%via NVD
CVE-2025-10018Medium· 4.8QuickCMS is vulnerable to multiple Stored XSS in language editor functionality (languages)
QuickCMS is vulnerable to multiple Stored XSS in language editor functionality (languages). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed on every page. By default…
▾ Sunlitopensolution · quick.cmsEPSS 0.18%via NVD