opensolution has 3 CVEs on record between 2025 and 2026. 1 was published in the last 90 days. The median CVSS is 6.9 (medium). Most affected products: quick.cms (2), Quick.Cart (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.9
- Publish → KEV
- —
- Last 90 days
- 1 prev 0
Worst active — by depth score
CVE-2026-41875Medium· 6.9Quick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel50CVE-2025-9982High· 7.5A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file and stored in plaintext41CVE-2025-10018Medium· 4.8QuickCMS is vulnerable to multiple Stored XSS in language editor functionality (languages)26
opensolution vulnerabilities
CVEs affecting opensolution, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-41875Medium· 6.9PoCQuick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel
Quick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request that changes admin's login and password. …
CVE-2025-9982High· 7.5A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file and stored in plaintext
A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file and stored in plaintext. This flaw allows attackers with access to the source code or the server file system to retrie…
CVE-2025-10018Medium· 4.8QuickCMS is vulnerable to multiple Stored XSS in language editor functionality (languages)
QuickCMS is vulnerable to multiple Stored XSS in language editor functionality (languages). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed on every page. By default…