Opensolution · Quick.Cms · CVE-2026-33386
**Name of the Vulnerable Software and Affected Versions**
QuickCMS versions prior to 6.8 patch published on 15.05.2026
**Description**
An issue exists due to an insecure HTTP-based plugin-fetching mechanism. A remote attacker can execute a Man-in-the-Middle (MITM) attack—a technique where an attacker intercepts communication between two parties—by impersonating the opensolution.org server. By serving arbitrary HTML or JavaScript at the plugin list endpoint, the malicious content is automatically fetched, rendered, and executed when a user accesses the plugin page, leading to Cross-Site Scripting (XSS).
**Recommendations**
Apply the patch for version 6.8 published on 15.05.2026.