Stored XSS Vulnerability in QuickCMS by OpenSolution
CVE-2025-9980
4.8MEDIUM
What is CVE-2025-9980?
QuickCMS contains a vulnerability in its page editor that allows a malicious admin to inject arbitrary HTML and JavaScript. When users visit a page that has been modified, the injected code is executed, potentially leading to unauthorized actions. While version 6.8 has been confirmed as vulnerable, other versions have not been thoroughly tested, indicating a risk that additional versions may also be affected.
Affected Version(s)
QuickCMS 6.8
