Opensolution maintains a focused portfolio of web-based content management, e-commerce, and community platforms—notably Quick CMS, Quick Cart, and Quick Forum—that serve small-to-medium deployments. The vendor's disclosures concentrate on application-layer input-handling vulnerabilities including cross-site scripting, SQL injection, and CSRF, reflecting the web-facing nature and integration demands of these systems. Vulnerabilities affecting this vendor frequently acquire public exploit code, consistent with the accessibility and remediation visibility of web application flaws. Defenders should monitor this vendor's release cycles for its installed base and prioritize patching in internet-exposed instances where input validation and session management weaknesses pose direct risk; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opensolution over time
Signals from CVEs in this vendor scope (45 CVEs).
45 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35754HIGH OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Languag | Jan 28, 2021 | 7.2 | 36 | NO | YES |
CVE-2026-11860HIGH Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. This allows attackers to tamper with serialized payloads in tra | Jun 15, 2026 | 7.5 | 34 | NO | NO |
CVE-2024-58308CRITICAL Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating the login form. Attackers can inject speci | Dec 11, 2025 | 9.8 | 31 | NO | NO |
CVE-2026-23796CRITICAL Quick.Cart allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker | Feb 5, 2026 | 9.8 | 29 | NO | NO |
CVE-2007-3138HIGH Directory traversal vulnerability in index.php in Open Solution Quick.Cart 2.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) i | Jun 8, 2007 | 7.5 | 29 | NO | YES |
CVE-2025-67684HIGH Quick.Cart is vulnerable to Local File Inclusion and Path Traversal issues in the theme selection mechanism. Quick.Cart allows a privileged user to upload arbitrary file contents w | Jan 22, 2026 | 7.2 | 28 | NO | NO |
CVE-2009-1410HIGH SQL injection vulnerability in index.php in Quick.Cms.Lite 0.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Apr 24, 2009 | 7.5 | 28 | NO | YES |
CVE-2007-3139MEDIUM config/general.php in Quick.Cart 2.2 and earlier uses a default username and password, which allows remote attackers to access the application via a login action to admin.php. NOT | Jun 8, 2007 | 6.8 | 27 | NO | YES |
CVE-2006-6390MEDIUM Multiple directory traversal vulnerabilities in Open Solution Quick.Cart 2.0, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include a | Dec 8, 2006 | 6.8 | 27 | NO | YES |
CVE-2006-6391MEDIUM Multiple directory traversal vulnerabilities in Open Solution Quick.Cart 2.0, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include a | Dec 8, 2006 | 6.8 | 27 | NO | YES |
Signals from CVEs in this vendor scope (45 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opensolution.
Media articles that mention a CVE ID that affects a product developed by Opensolution — matched by CVE ID, not by vendor name.