Quick.Cart

Vendor:

First CVE: May 11, 2005 · Active for 21 years

16
Total CVEs
More Total CVEs than 83% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Quick.Cart over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 11, 2005
21 years ago
Most Recent CVE
Feb 5, 2026
169 days ago

CVE Severity & Scoring

Quick.Cart16 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network5 (31.3%)
Unknown11 (68.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (31.3%)
High0 (0.0%)
Unknown11 (68.8%)
User Interaction
None4 (25.0%)
Unknown11 (68.8%)
Required1 (6.3%)
Privileges Required
Low0 (0.0%)
High3 (18.8%)
None2 (12.5%)
Unknown11 (68.8%)

Top CVEs

Signals from CVEs in this product scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Languag
Jan 28, 20217.236NOYES
Quick.Cart allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker
Feb 5, 20269.829NONO
Directory traversal vulnerability in index.php in Open Solution Quick.Cart 2.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) i
Jun 8, 20077.529NOYES
Quick.Cart is vulnerable to Local File Inclusion and Path Traversal issues in the theme selection mechanism. Quick.Cart allows a privileged user to upload arbitrary file contents w
Jan 22, 20267.228NONO
config/general.php in Quick.Cart 2.2 and earlier uses a default username and password, which allows remote attackers to access the application via a login action to admin.php. NOT
Jun 8, 20076.827NOYES
Multiple directory traversal vulnerabilities in Open Solution Quick.Cart 2.0, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include a
Dec 8, 20066.827NOYES
Multiple directory traversal vulnerabilities in Open Solution Quick.Cart 2.0, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include a
Dec 8, 20066.827NOYES
Cross-site scripting (XSS) vulnerability in Open Solution Quick.Cms 5.0 and Quick.Cart 6.0, possibly as downloaded before December 19, 2012, allows remote attackers to inject arbit
Mar 24, 20144.326NOYES
Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote attackers to hijack the authentication of the administrator for requests that (1) delete o
Dec 1, 20096.826NOYES
Quick.Cart is vulnerable to reflected XSS via the sSort parameter. An attacker can craft a malicious URL which, when opened, results in arbitrary JavaScript execution in the victim
Jan 22, 20266.125NONO

Exploit Exposure

Signals from CVEs in this product scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
9 CVEs
56.2% of CVEs· 93rd percentile

Social Chatter

Signals from CVEs in this product scope (16 CVEs).

Media Mentions

Signals from CVEs in this product scope (16 CVEs).

Top CNAs Publishing CVEs For Quick.Cart

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.747.00.4%00
6.014.33.9%01
5.015.01.4%00
3.416.81.0%01
3.114.31.5%01
2.026.82.0%02
0.3.014.31.7%01
0.317.51.2%00