CVE-2026-94110 | QCMS up to 6.0.6 Content Detail Page Controllers.php self_Tmp ID sql injection
A vulnerability categorized as critical has been discovered in QCMS up to 6.0.6. This issue affects the function self_Tmp in the library Lib/Config/Controllers.php of the component Content Detail Page. Such manipulation of the argument ID leads to sql injection.
This vulnerability is listed as CVE-2026-94110. The attack may be performed from remote. In addition, an exploit is available.
Router uses raw REQUEST_URI without URL decoding, so payloads must contain literal spaces – %20 never decodes before route parsing. The support team of the vendor was contacted early about this disclosure. Unfortunately, they responded just with profanity.VulDB Recent EntriesRead More