PatchSiren

QCMS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM QCMS CVE published 2026-09-21

CVE-2026-94110

A security vulnerability has been detected in QCMS up to 6.0.6. This issue affects the function self_Tmp in the library Lib/Config/Controllers.php of the component Content Detail Page. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. Router uses raw REQUEST_URI without URL decoding, so payloads must contain literal spaces - %20 never decodes before rout [truncated]