Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Quickbox

First CVE: Jun 1, 2020Active for: 6 yearsTotal CVEs: 5

Quickbox is a niche media server and file-hosting platform whose vulnerability profile centers on its core product and clusters around application-level control-flow and input-handling issues, particularly OS command injection, cross-site scripting, improper privilege management, and missing authentication for critical functions. These weaknesses reflect common risks in self-hosted web applications that handle user input and system administration; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
5
Total CVEs
More Total CVEs than 83% of tracked vendors
2.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Quickbox over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 1, 2020
6 years ago
Most Recent CVE
Feb 7, 2022
1,628 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-13448HIGH
QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicesta
Jun 1, 20208.840NOYES
CVE-2020-13694HIGH
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysql without a password, which means that the www-data user can
Jun 1, 20208.828NONO
CVE-2020-13695HIGH
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as root without a password, which allows an a
Jun 1, 20207.224NONO
CVE-2021-44981HIGH
In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it into a shell_exec(''); function without properly sanitizing any
Jan 24, 20228.823NONO
CVE-2021-45281MEDIUM
QuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the user supplied input for the value of this parameter is not pro
Feb 7, 20226.122NONO
View all 5 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products5 CVEs
20%
80%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (80.0%)
Unknown0 (0.0%)
Required1 (20.0%)
Privileges Required
Low3 (60.0%)
High1 (20.0%)
None1 (20.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
20.0% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Quickbox.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Quickbox — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Quickbox's Products

View all 1 CNAs →

Top CWEs