QDOCS records
6 published records for vendor qdocs.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 16.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-5495No exploit | QDocs Smart School HTTP POST Request sql injectionqdocs · smart school · CWE-89 | Critical9.8 | — | 1.1% | Oct 10, 2023 |
28Monitor | CVE-2025-60500Proof of concept | QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictiqdocs · smart school · CWE-434 | High7.2 | — | 0.5% | Oct 21, 2025 |
24Monitor | CVE-2024-34240No exploit | QDOCS Smart School 7.0.0 is vulnerable to Cross Site Scripting (XSS) resulting in arbitrary code execution in admin functions related to addqdocs · smart school · CWE-79 | Medium6.1 | — | 0.4% | May 21, 2024 |
21Monitor | CVE-2024-8784No exploit | QDocs Smart School Management System Chat mynewuser sql injectionqdocs · smart school · CWE-89 | Medium5.3 | — | 0.5% | Sep 13, 2024 |
20Monitor | CVE-2025-41107No exploit | Stored XSS in Smart Schoolqdocs · smart school · CWE-79 | Medium5.1 | — | 0.2% | Nov 10, 2025 |
19Monitor | CVE-2020-36011No exploit | A cross-site scripting (XSS) issue in Add Patient Form in QDOCS Smart Hospital Management System 3.1 allows a remote attacker to inject arbiqdocs · smart hospital · CWE-79 | Medium4.8 | — | 0.7% | Jan 26, 2021 |
- CVE-2023-549539Monitor
QDocs Smart School HTTP POST Request sql injection
CriticalCVSS 9.8No exploitEPSS 1%qdocs · smart schoolOct 10, 2023
- CVE-2025-6050028Monitor
QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restricti
HighCVSS 7.2Proof of conceptEPSS 1%qdocs · smart schoolOct 21, 2025
- CVE-2024-3424024Monitor
QDOCS Smart School 7.0.0 is vulnerable to Cross Site Scripting (XSS) resulting in arbitrary code execution in admin functions related to add
MediumCVSS 6.1No exploitEPSS 0%qdocs · smart schoolMay 21, 2024
- CVE-2024-878421Monitor
QDocs Smart School Management System Chat mynewuser sql injection
MediumCVSS 5.3No exploitEPSS 1%qdocs · smart schoolSep 13, 2024
- CVE-2025-4110720Monitor
Stored XSS in Smart School
MediumCVSS 5.1No exploitEPSS 0%qdocs · smart schoolNov 10, 2025
- CVE-2020-3601119Monitor
A cross-site scripting (XSS) issue in Add Patient Form in QDOCS Smart Hospital Management System 3.1 allows a remote attacker to inject arbi
MediumCVSS 4.8No exploitEPSS 1%qdocs · smart hospitalJan 26, 2021