CVE-2026-63302
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
28/07/2026
Last modified:
30/07/2026
Description
Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated attacker with admin privileges can include arbitrary files located within the application&#39;s directory structure via a crafted HTTP request. Successful exploitation allows disclosure of the server&#39;s directory structure and absolute file paths (path disclosure).<br />
<br />
<br />
<br />
The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.
Impact
Base Score 4.0
5.10
Severity 4.0
MEDIUM



