qcubed CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

qcubed vulnerability overview

Aggregates CVE and security vulnerability intelligence across all qcubed-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk sql injection and vendor risk cross-site scripting; exposure may include vendor impact session compromise and vendor impact data exposure in vendor surface production workloads contexts.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2020-24914 A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to execute code via a crafted POST request. [email protected] 9.8 5.55% 2021-03-04 2026-06-17
CVE-2020-24913 A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request. [email protected] 9.8 44.00% 2021-03-04 2026-06-17
CVE-2020-24912 A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users. [email protected] 6.1 6.29% 2021-03-04 2026-06-17
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence