quickappscms records
3 published records for vendor quickappscms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 33.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2018-9108No exploit | CSRF in /admin/user/manage/add in QuickAppsCMS 2.0.0-beta2 allows an unauthorized remote attacker to create an account with admin privilegesquickappscms · quickapps cms · CWE-352 | High8.8 | — | 0.8% | Mar 28, 2018 |
35Monitor | CVE-2018-17102No exploit | An issue was discovered in QuickAppsCMS (aka QACMS) through 2.0.0-beta2.quickappscms · quickapps cms · CWE-352 | High8.8 | — | 0.7% | Sep 16, 2018 |
21Monitor | CVE-2017-1000495No exploit | QuickApps CMS version 2.0.0 is vulnerable to Stored Cross-site Scripting in the user's real name field resulting in denial of service and pequickappscms · quickapps cms · CWE-79 | Medium5.4 | — | 0.6% | Jan 3, 2018 |
- CVE-2018-910835Monitor
CSRF in /admin/user/manage/add in QuickAppsCMS 2.0.0-beta2 allows an unauthorized remote attacker to create an account with admin privileges
HighCVSS 8.8No exploitEPSS 1%quickappscms · quickapps cmsMar 28, 2018
- CVE-2018-1710235Monitor
An issue was discovered in QuickAppsCMS (aka QACMS) through 2.0.0-beta2.
HighCVSS 8.8No exploitEPSS 1%quickappscms · quickapps cmsSep 16, 2018
- CVE-2017-100049521Monitor
QuickApps CMS version 2.0.0 is vulnerable to Stored Cross-site Scripting in the user's real name field resulting in denial of service and pe
MediumCVSS 5.4No exploitEPSS 1%quickappscms · quickapps cmsJan 3, 2018