Vulnerabilities
Vulnerable Software
Security Vulnerabilities
QuickCMS is vulnerable to Cross-Site Request Forgery in article creation functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request creating a malicious article with content defined by the attacker. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
CVSS Score
4.3
EPSS Score
0.0
Published
2025-08-20
QuickCMS.EXT is vulnerable to Reflected XSS in sFileName parameter in thumbnail viewer functionality.  An attacker can craft a malicious URL that results in arbitrary JavaScript execution in the victim's browser when opened. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
CVSS Score
6.1
EPSS Score
0.0
Published
2025-08-20
In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership
CVSS Score
7.5
EPSS Score
0.0
Published
2025-08-20
In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content
CVSS Score
5.5
EPSS Score
0.0
Published
2025-08-20
In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files
CVSS Score
4.3
EPSS Score
0.0
Published
2025-08-20
In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference
CVSS Score
4.7
EPSS Score
0.0
Published
2025-08-20
In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files
CVSS Score
6.5
EPSS Score
0.0
Published
2025-08-20
In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start
CVSS Score
6.5
EPSS Score
0.0
Published
2025-08-20
In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature
CVSS Score
5.2
EPSS Score
0.0
Published
2025-08-20
In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content
CVSS Score
8.7
EPSS Score
0.001
Published
2025-08-20


Contact Us

Shodan ® - All rights reserved