πŸ” CVE Alert

CVE-2026-41874

UNKNOWN 0.0

Hard-coded admin credentials in Quick.Cart

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with access to the server file system to retrieve authentication details, potentially leading to privilege escalation. The vendor assessed the likelihood of exploitation as very low and determined that a fix isΒ not necessary. Only version 6.7 was tested but all versions should be considered as vulnerable.

CWE CWE-256
Vendor opensolution
Product quick.cart
Published Jul 28, 2026
Stay Ahead of the Next One

Get instant alerts for opensolution quick.cart

Be the first to know when new unknown vulnerabilities affecting opensolution quick.cart are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

OpenSolution / Quick.Cart
0 ≀ 6.7

References

NVD β†— CVE.org β†— EPSS Data β†—
cert.pl: https://cert.pl/posts/2026/07/CVE-2026-41874/ opensolution.org: https://opensolution.org/shopping-cart-quick-cart.html

Credits

Karol Czubernat