PT-2026-44894 · Opensolution · Quick.Cms

·

CVE-2026-33386

·

Published

2026-05-29

·

Updated

2026-07-21

CVSS v4.0

2.3

Low

VectorAV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions QuickCMS versions prior to 6.8 patch published on 15.05.2026
Description An issue exists due to an insecure HTTP-based plugin-fetching mechanism. A remote attacker can execute a Man-in-the-Middle (MITM) attack—a technique where an attacker intercepts communication between two parties—by impersonating the opensolution.org server. By serving arbitrary HTML or JavaScript at the plugin list endpoint, the malicious content is automatically fetched, rendered, and executed when a user accesses the plugin page, leading to Cross-Site Scripting (XSS).
Recommendations Apply the patch for version 6.8 published on 15.05.2026.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33386

Affected Products

Quick.Cms