PT-2025-43436 · Quick.Cms · Quick.Cms

Published

2025-10-23

·

Updated

2025-11-17

·

CVE-2025-9980

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions QuickCMS version 6.8 QuickCMS (affected versions not specified)
Description QuickCMS is susceptible to multiple Stored Cross-Site Scripting (XSS) issues within the page editor functionality, specifically in the 'pages-form' component. An attacker possessing administrative privileges can inject arbitrary HTML and JavaScript code into a website. This injected code will be rendered and executed when a user visits the modified page. By default, the administrative user is restricted from adding JavaScript to the website.
Recommendations QuickCMS version 6.8: Address the Stored XSS issue in the 'pages-form' component to prevent arbitrary HTML and JavaScript injection. QuickCMS (affected versions not specified): Address the Stored XSS issue in the 'pages-form' component to prevent arbitrary HTML and JavaScript injection.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-9980

Affected Products

Quick.Cms