Qcms is a color-management library with a narrowly scoped product footprint that appears in rendering and display pipelines across various applications and systems. The vulnerabilities observed center on the product's input-handling role, with a recurring signal in cross-site scripting weaknesses tied to improper neutralization during web-page generation. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Qcms over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14978HIGH An issue was discovered in QCMS 3.0.1. CSRF exists via the backend/user/admin/add.html URI. | Aug 6, 2018 | 8.8 | 27 | NO | NO |
CVE-2025-50233MEDIUM A vulnerability in QCMS version 6.0.5 allows authenticated users to read arbitrary files from the server due to insufficient validation of the "Name" parameter in the backend templ | Aug 6, 2025 | 6.5 | 22 | NO | NO |
CVE-2018-14977MEDIUM An issue was discovered in QCMS 3.0.1. upload/System/Controller/guest.php has XSS, as demonstrated by the name parameter, a different vulnerability than CVE-2018-8070. | Aug 6, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-8070MEDIUM QCMS version 3.0 has XSS via the title parameter to the /guest/index.html URI. | Mar 12, 2018 | 5.4 | 21 | NO | NO |
CVE-2020-10578HIGH An arbitrary file read vulnerability exists in system/controller/backend/template.php in QCMS v3.0.1. | Mar 14, 2020 | 7.5 | 19 | NO | NO |
CVE-2018-14976MEDIUM An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/category.php has XSS. | Aug 6, 2018 | 4.8 | 19 | NO | NO |
CVE-2018-14973MEDIUM An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/product.php has XSS. | Aug 6, 2018 | 4.8 | 19 | NO | NO |
CVE-2018-8069MEDIUM QCMS version 3.0 has XSS via the webname parameter to the /backend/system.html URI. | Mar 12, 2018 | 5.4 | 19 | NO | NO |
CVE-2018-14975MEDIUM An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/album.php has XSS. | Aug 6, 2018 | 4.8 | 18 | NO | NO |
CVE-2018-14974MEDIUM An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/news.php has XSS. | Aug 6, 2018 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Qcms.
Media articles that mention a CVE ID that affects a product developed by Qcms — matched by CVE ID, not by vendor name.