Qcms · Qcms · CVE-2026-94110
**Name of the Vulnerable Software and Affected Versions**
QCMS versions prior to 6.0.7
**Description**
A remote SQL injection exists in the Content Detail Page component within the `self Tmp()` function located in the `Lib/Config/Controllers.php` library. The issue occurs when the `ID` argument is manipulated. Additionally, the router utilizes the raw `REQUEST URI` without URL decoding, meaning payloads must contain literal spaces because `%20` is not decoded before route parsing.
**Recommendations**
Update QCMS to a version newer than 6.0.6.
As a temporary mitigation, restrict access to the `self Tmp()` function in the `Lib/Config/Controllers.php` library.