CVE Watchtower


← Back to CVE List

CVE-2026-33386NVD

Vulnerability Summary

QuickCMS is vulnerable to Cross-Site Scripting (XSS) through its insecure HTTP-based plugin‑fetching mechanism. A malicious attacker can perform a Man‑in‑the‑Middle (MITM) attack by impersonating the opensolution.org server and serving arbitrary HTML or JavaScript at the plugin list endpoint. When a user accesses the plugin page, the malicious content is automatically fetched, rendered, and executed.


This issue was fixed in a patch to version 6.8 published on 15.05.2026, deployments without this patch are still vulnerable.
Severity Level
UNKNOWN
Published Date
May 29, 2026
Last Modified
May 29, 2026
Exploitation Status
????
EPSS Score (30-Day)
0.03%Probability
Root Weakness (CWE)
N/A