Quickbox is a niche media server and file-hosting platform whose vulnerability profile centers on its core product and clusters around application-level control-flow and input-handling issues, particularly OS command injection, cross-site scripting, improper privilege management, and missing authentication for critical functions. These weaknesses reflect common risks in self-hosted web applications that handle user input and system administration; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Quickbox over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13448HIGH QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicesta | Jun 1, 2020 | 8.8 | 40 | NO | YES |
CVE-2020-13694HIGH In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysql without a password, which means that the www-data user can | Jun 1, 2020 | 8.8 | 28 | NO | NO |
CVE-2020-13695HIGH In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as root without a password, which allows an a | Jun 1, 2020 | 7.2 | 24 | NO | NO |
CVE-2021-44981HIGH In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it into a shell_exec(''); function without properly sanitizing any | Jan 24, 2022 | 8.8 | 23 | NO | NO |
CVE-2021-45281MEDIUM QuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the user supplied input for the value of this parameter is not pro | Feb 7, 2022 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Quickbox.
Media articles that mention a CVE ID that affects a product developed by Quickbox — matched by CVE ID, not by vendor name.