# QuickCMS patches session fixation, XSS flaws

Published: 2026-05-29 · Severity: medium
Canonical: https://vorant.io/reports/9a24fb3e-1f08-5d35-961f-cdfdaee61cd8/quickcms-patches-session-fixation-xss-flaws

> Two vulnerabilities in QuickCMS allow session hijacking via fixation and XSS through insecure HTTP plugin fetching, patched in version 6.8.

CERT Polska coordinated disclosure of two vulnerabilities affecting QuickCMS. CVE-2026-33384 is a session fixation flaw where a session identifier can be set prior to authentication and remains unchanged afterward, allowing an attacker to pre-set a victim's session ID and later hijack the authenticated session. CVE-2026-33386 stems from QuickCMS fetching its plugin list over insecure HTTP, enabling a man-in-the-middle attacker to impersonate the opensolution.org server and inject arbitrary HTML or JavaScript that executes automatically when a user views the plugin page, resulting in cross-site scripting.

Both issues were addressed in QuickCMS version 6.8, released May 15, 2026. Deployments that have not applied this update remain vulnerable to session hijacking and client-side script injection via the plugin-fetching mechanism. No evidence of active exploitation is indicated in the advisory; this is a coordinated disclosure with a patch already available.

## Mentioned in this report

- Vulnerabilities: CVE-2026-33384, CVE-2026-33386

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-33384

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/9a24fb3e-1f08-5d35-961f-cdfdaee61cd8/quickcms-patches-session-fixation-xss-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
