Cyber News / Article / Vulnerabilities in QuickCMS software

Vulnerabilities in QuickCMS software
CERT Polska has received a report about vulnerabilities in QuickCMS software and participated in coordination of their disclosure.
The vulnerabilityCVE-2026-33384: QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session.
The vulnerabilityCVE-2026-33386: QuickCMS is vulnerable to Cross-Site Scripting (XSS) through its insecure HTTP-based pluginâfetching mechanism. A malicious attacker can perform a ManâinâtheâMiddle (MITM) attack by impersonating the opensolution.org server and serving arbitrary HTML or JavaScript at the plugin list endpoint. When a user accesses the plugin page, the malicious content is automatically fetched, rendered, and executed.
These issues were fixed in a patch to version 6.8 published on 15.05.2026, deployments without this patch are still vulnerable.
We thank Jakub LipiÅski for the responsible vulnerability report.
Related articles
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
8 days ago
Top 10 Best Patch Management Software in 2026
2 days ago
September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs
3 days ago
You might Also like

Hackers Target Claude, Cursor and Codex AI Agents to Steal Tokens and Prompt Histories

DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

