Known Vulnerabilities for Qcms by Q-cms
Listed below are 10 of the newest known vulnerabilities associated with "Qcms" by "Q-cms".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-10578 json | An arbitrary file read vulnerability exists in system/controller/backend/template.php in QCMS v3.0.1. | 7.5 - HIGH | 2020-03-14 | 2021-07-21 |
| CVE-2018-14978 json | An issue was discovered in QCMS 3.0.1. CSRF exists via the backend/user/admin/add.html URI. | 8.8 - HIGH | 2018-08-06 | 2018-10-03 |
| CVE-2018-14977 json | An issue was discovered in QCMS 3.0.1. upload/System/Controller/guest.php has XSS, as demonstrated by the name parameter, a d... | 6.1 - MEDIUM | 2018-08-06 | 2018-10-03 |
| CVE-2018-14976 json | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/category.php has XSS. | 4.8 - MEDIUM | 2018-08-06 | 2018-10-03 |
| CVE-2018-14975 json | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/album.php has XSS. | 4.8 - MEDIUM | 2018-08-06 | 2018-10-03 |
| CVE-2018-14974 json | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/news.php has XSS. | 4.8 - MEDIUM | 2018-08-06 | 2018-10-03 |
| CVE-2018-14973 json | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/product.php has XSS. | 4.8 - MEDIUM | 2018-08-06 | 2018-10-03 |
| CVE-2018-14972 json | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/down.php has XSS. | 4.8 - MEDIUM | 2018-08-06 | 2018-10-03 |
| CVE-2018-14971 json | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/user.php has XSS. | 4.8 - MEDIUM | 2018-08-06 | 2018-10-03 |
| CVE-2018-14970 json | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/slideshow.php has XSS. | 4.8 - MEDIUM | 2018-08-06 | 2018-10-03 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Q-cms | Qcms | 3.0.1 |