Vendor
OpenSolution vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 10 vulnerabilities in OpenSolution: 0 in the last 7 days and 5 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-33385, was published on 29 July 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 5
- Critical, all time
- 0
- Exploited in the wild
- 0
About OpenSolution
OpenSolution is a software developer specializing in e-commerce and content management systems, including Quick.Cart and Quick.Cms.
OpenSolution technologies
Latest OpenSolution vulnerabilities
- CVE-2026-33385: OpenSolution Quick.CMS Blind SQL injection in administration panelinfoCVSS 5.1
- CVE-2026-41874: OpenSolution Quick.Cart plaintext admin credentials in configuration fileinfoCVSS 6.8
- CVE-2026-63303: OpenSolution Quick.CMS path traversal in URI pathinfoCVSS 5.1
- CVE-2026-63302: OpenSolution Quick.CMS Local File Inclusion in admin.phpinfoCVSS 5.1
- CVE-2026-63301: OpenSolution Quick.CMS Denial of Service via primary language deletioninfoCVSS 7
- CVE-2026-11860: OpenSolution Quick.CMS insecure deserialization in admin panelinfoCVSS 7.5
- CVE-2026-33386: OpenSolution QuickCMS Cross-Site Scripting via insecure plugin fetchinginfoCVSS 0
- CVE-2026-33384: OpenSolution QuickCMS session fixationinfoCVSS 0
- CVE-2021-47981: OpenSolution Quick.CMS XSS in sliders formmediumCVSS 5.4
- CVE-2026-1468: QuickCMS Cross-Site Request Forgery in formsinfoCVSS 0EPSS 0.2%
Most severe OpenSolution vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2021-47981: OpenSolution Quick.CMS XSS in sliders formmediumCVSS 5.4
- CVE-2026-11860: OpenSolution Quick.CMS insecure deserialization in admin panelinfoCVSS 7.5
- CVE-2026-63301: OpenSolution Quick.CMS Denial of Service via primary language deletioninfoCVSS 7
- CVE-2026-41874: OpenSolution Quick.Cart plaintext admin credentials in configuration fileinfoCVSS 6.8
- CVE-2026-33385: OpenSolution Quick.CMS Blind SQL injection in administration panelinfoCVSS 5.1
- CVE-2026-63303: OpenSolution Quick.CMS path traversal in URI pathinfoCVSS 5.1
- CVE-2026-63302: OpenSolution Quick.CMS Local File Inclusion in admin.phpinfoCVSS 5.1
- CVE-2026-1468: QuickCMS Cross-Site Request Forgery in formsinfoCVSS 0EPSS 0.2%
- CVE-2026-33386: OpenSolution QuickCMS Cross-Site Scripting via insecure plugin fetchinginfoCVSS 0
- CVE-2026-33384: OpenSolution QuickCMS session fixationinfoCVSS 0
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 5 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/opensolution.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "OpenSolution vulnerabilities", https://junglewise.ai/threats/vendors/opensolution, 26 September 2026.