VulnSea

qcubed has 3 CVEs on record. The median CVSS is 9.8 (critical), with 2 rated critical.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
9.8
Publish → KEV
Last 90 days
0 prev 0

Products

  • qcubed 3
3
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

qcubed vulnerabilities

CVEs affecting qcubed, newest first. Open any entry for full detail, references, and exploit status.

3 CVEsRSS

CVE-2020-24912Medium· 6.1PoC
5y ago

A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.

A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.

Twilightqcubed · qcubedEPSS 6.3%via NVD
CVE-2020-24914Critical· 9.8
5y ago

A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to execute code via a crafted POST request.

A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to execute code via a crafted POST request.

Midnightqcubed · qcubedEPSS 5.0%via NVD
CVE-2020-24913Critical· 9.8PoC
5y ago

A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.

A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.

Abyssalqcubed · qcubedEPSS 41%via NVD
qcubed vulnerabilities (CVEs) · VulnSea