Open Solution's vulnerability profile centers on a narrow line of e-commerce and community forum software, with recurrent exposure in products such as Quick.Cart and Quick.Forum. These disclosures frequently acquire public exploit tooling, reflecting the accessibility and appeal of web-facing applications to the broader security research and development community. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Open Solution over time
Signals from CVEs in this vendor scope (45 CVEs).
45 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35754HIGH OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Languag | Jan 28, 2021 | 7.2 | 36 | NO | YES |
CVE-2026-11860HIGH Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. This allows attackers to tamper with serialized payloads in tra | Jun 15, 2026 | 7.5 | 34 | NO | NO |
CVE-2024-58308CRITICAL Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating the login form. Attackers can inject speci | Dec 11, 2025 | 9.8 | 31 | NO | NO |
CVE-2026-23796CRITICAL Quick.Cart allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker | Feb 5, 2026 | 9.8 | 29 | NO | NO |
CVE-2007-3138HIGH Directory traversal vulnerability in index.php in Open Solution Quick.Cart 2.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) i | Jun 8, 2007 | 7.5 | 29 | NO | YES |
CVE-2025-67684HIGH Quick.Cart is vulnerable to Local File Inclusion and Path Traversal issues in the theme selection mechanism. Quick.Cart allows a privileged user to upload arbitrary file contents w | Jan 22, 2026 | 7.2 | 28 | NO | NO |
CVE-2009-1410HIGH SQL injection vulnerability in index.php in Quick.Cms.Lite 0.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Apr 24, 2009 | 7.5 | 28 | NO | YES |
CVE-2007-3139MEDIUM config/general.php in Quick.Cart 2.2 and earlier uses a default username and password, which allows remote attackers to access the application via a login action to admin.php. NOT | Jun 8, 2007 | 6.8 | 27 | NO | YES |
CVE-2006-6390MEDIUM Multiple directory traversal vulnerabilities in Open Solution Quick.Cart 2.0, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include a | Dec 8, 2006 | 6.8 | 27 | NO | YES |
CVE-2006-6391MEDIUM Multiple directory traversal vulnerabilities in Open Solution Quick.Cart 2.0, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include a | Dec 8, 2006 | 6.8 | 27 | NO | YES |
Signals from CVEs in this vendor scope (45 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Open Solution.
Media articles that mention a CVE ID that affects a product developed by Open Solution — matched by CVE ID, not by vendor name.