OpenSolution / Quick.Cart
16 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-41875 | Cross-Site Request Forgery in admin panel of Quick.Cart | MEDIUM | 6.9 | Sep 29, 2026 |
| CVE-2026-41874 | Hard-coded admin credentials in Quick.Cart | MEDIUM | 6.8 | Jul 28, 2026 |
| CVE-2026-23796 | Session Fixation in Quick.Cart | MEDIUM | 4.8 | Feb 5, 2026 |
| CVE-2026-23797 | Plaintext password display in Quick.Cart | MEDIUM | 6.9 | Feb 5, 2026 |
| CVE-2025-67684 | Remote Code Execution via Local File Inclusion in Quick.Cart | CRITICAL | 9.4 | Jan 22, 2026 |
| CVE-2025-67683 | Reflected XSS in Quick.Cart | MEDIUM | 5.1 | Jan 22, 2026 |
| CVE-2025-10317 | Multiple Cross-Site Request Forgery in Quick.Cart | MEDIUM | 5.1 | Oct 30, 2025 |
| CVE-2020-35754 | OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input… | HIGH | 7.2 | Jan 28, 2021 |
| CVE-2012-6430 | Cross-site scripting (XSS) vulnerability in Open Solution Quick.Cms 5.0 and Quick.Cart 6.0, possibly as downloaded before December 19, 2012, allows remote atta… | MEDIUM | 4.3 | Mar 24, 2014 |
| CVE-2012-6049 | Open Solution Quick.Cart 5.0 allows remote attackers to obtain sensitive information via (1) a long string or (2) invalid characters in a cookie, which reveals… | MEDIUM | 5.0 | Nov 27, 2012 |
| CVE-2009-4120 | Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote attackers to hijack the authentication of the administrator for reque… | MEDIUM | 6.8 | Dec 1, 2009 |
| CVE-2008-4140 | Cross-site scripting (XSS) vulnerability in admin.php in Quick.Cart 3.1 allows remote attackers to inject arbitrary web script or HTML via the query string. | MEDIUM | 4.3 | Sep 19, 2008 |
| CVE-2007-3139 | config/general.php in Quick.Cart 2.2 and earlier uses a default username and password, which allows remote attackers to access the application via a login acti… | MEDIUM | 6.8 | Jun 8, 2007 |
| CVE-2007-3138 | Directory traversal vulnerability in index.php in Open Solution Quick.Cart 2.2 and earlier allows remote attackers to include and execute arbitrary local files… | HIGH | 7.5 | Jun 8, 2007 |
| CVE-2007-1407 | Unspecified vulnerability in OpenSolution Quick.Cart before 2.1 has unknown impact and attack vectors, related to a "low critical exploit." | HIGH | 7.5 | Mar 10, 2007 |
| CVE-2006-6391 | Multiple directory traversal vulnerabilities in Open Solution Quick.Cart 2.0, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote a… | MEDIUM | 6.8 | Dec 8, 2006 |
| CVE-2006-6390 | Multiple directory traversal vulnerabilities in Open Solution Quick.Cart 2.0, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote a… | MEDIUM | 6.8 | Dec 8, 2006 |
| CVE-2005-1588 | SQL injection vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to execute arbitrary SQL commands via the iCategory parameter. NOTE: the… | HIGH | 7.5 | May 14, 2005 |
| CVE-2005-1587 | Cross-site scripting (XSS) vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to inject arbitrary web script or HTML via the sWord paramet… | MEDIUM | 4.3 | May 14, 2005 |
Showing 1 to 16 of 16 CVEs