Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Opensolution

First CVE: May 11, 2005Active for: 21 yearsTotal CVEs: 45
24.1
VTI Score
Low

Opensolution maintains a focused portfolio of web-based content management, e-commerce, and community platforms—notably Quick CMS, Quick Cart, and Quick Forum—that serve small-to-medium deployments. The vendor's disclosures concentrate on application-layer input-handling vulnerabilities including cross-site scripting, SQL injection, and CSRF, reflecting the web-facing nature and integration demands of these systems. Vulnerabilities affecting this vendor frequently acquire public exploit code, consistent with the accessibility and remediation visibility of web application flaws. Defenders should monitor this vendor's release cycles for its installed base and prioritize patching in internet-exposed instances where input validation and session management weaknesses pose direct risk; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
45
Total CVEs
More Total CVEs than 98% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Opensolution over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 11, 2005
21 years ago
Most Recent CVE
Jun 15, 2026
39 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (45 CVEs).

45 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-35754HIGH
OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Languag
Jan 28, 20217.236NOYES
CVE-2026-11860HIGH
Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. This allows attackers to tamper with serialized payloads in tra
Jun 15, 20267.534NONO
CVE-2024-58308CRITICAL
Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating the login form. Attackers can inject speci
Dec 11, 20259.831NONO
CVE-2026-23796CRITICAL
Quick.Cart allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker
Feb 5, 20269.829NONO
CVE-2007-3138HIGH
Directory traversal vulnerability in index.php in Open Solution Quick.Cart 2.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) i
Jun 8, 20077.529NOYES
CVE-2025-67684HIGH
Quick.Cart is vulnerable to Local File Inclusion and Path Traversal issues in the theme selection mechanism. Quick.Cart allows a privileged user to upload arbitrary file contents w
Jan 22, 20267.228NONO
CVE-2009-1410HIGH
SQL injection vulnerability in index.php in Quick.Cms.Lite 0.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Apr 24, 20097.528NOYES
CVE-2007-3139MEDIUM
config/general.php in Quick.Cart 2.2 and earlier uses a default username and password, which allows remote attackers to access the application via a login action to admin.php. NOT
Jun 8, 20076.827NOYES
CVE-2006-6390MEDIUM
Multiple directory traversal vulnerabilities in Open Solution Quick.Cart 2.0, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include a
Dec 8, 20066.827NOYES
CVE-2006-6391MEDIUM
Multiple directory traversal vulnerabilities in Open Solution Quick.Cart 2.0, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include a
Dec 8, 20066.827NOYES
View all 45 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products45 CVEs
71%
22%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (4.4%)
Network22 (48.9%)
Unknown20 (44.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low25 (55.6%)
High0 (0.0%)
Unknown20 (44.4%)
User Interaction
None7 (15.6%)
Unknown20 (44.4%)
Required17 (37.8%)
Privileges Required
Low5 (11.1%)
High9 (20.0%)
None11 (24.4%)
Unknown20 (44.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (45 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
12 CVEs
26.7% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Opensolution.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Opensolution — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Opensolution's Products

View all 3 CNAs →

Top CWEs