QuickCMS patches session fixation, XSS flaws
Two vulnerabilities in QuickCMS allow session hijacking via fixation and XSS through insecure HTTP plugin fetching, patched in version 6.8.
CERT Polska coordinated disclosure of two vulnerabilities affecting QuickCMS. CVE-2026-33384 is a session fixation flaw where a session identifier can be set prior to authentication and remains unchanged afterward, allowing an attacker to pre-set a victim's session ID and later hijack the authenticated session. CVE-2026-33386 stems from QuickCMS fetching its plugin list over insecure HTTP, enabling a man-in-the-middle attacker to impersonate the opensolution.org server and inject arbitrary HTML or JavaScript that executes automatically when a user views the plugin page, resulting in cross-site scripting.
Both issues were addressed in QuickCMS version 6.8, released May 15, 2026. Deployments that have not applied this update remain vulnerable to session hijacking and client-side script injection via the plugin-fetching mechanism. No evidence of active exploitation is indicated in the advisory; this is a coordinated disclosure with a patch already available.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-33384
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free