Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Keep06

#37759of 57,349
7.5Total CVSS
Vulnerabilities · 1
PT-2026-96030
7.5
2026-09-21
Qcms · Qcms · CVE-2026-94110
**Name of the Vulnerable Software and Affected Versions** QCMS versions prior to 6.0.7 **Description** A remote SQL injection exists in the Content Detail Page component within the `self Tmp()` function located in the `Lib/Config/Controllers.php` library. The issue occurs when the `ID` argument is manipulated. Additionally, the router utilizes the raw `REQUEST URI` without URL decoding, meaning payloads must contain literal spaces because `%20` is not decoded before route parsing. **Recommendations** Update QCMS to a version newer than 6.0.6. As a temporary mitigation, restrict access to the `self Tmp()` function in the `Lib/Config/Controllers.php` library.