CVE-2026-41874

Hard-coded admin credentials in Quick.Cart

Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with access to the server file system to retrieve authentication details, potentially leading to privilege escalation. The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary. Only version 6.7 was tested but all versions should be considered as vulnerable.


We have discovered 640 live websites that are affected by CVE-2026-41874.

Run a Free Instant Scan




Affected Software

Product  Quick.Cart
Category Ecommerce
Vulnerable Domains640 live websites (100% of Quick.Cart install base)
Vulnerable Versions
  • from 0 through 6.7
Vulnerable Versions Count10 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-256 Plaintext Storage of a Password



Details

  • Published - Jul 28, 2026
  • Updated - Jul 28, 2026

Credits

  • Karol Czubernat (finder)

Website Distribution by Country

Number of websites using CVE-2026-41874
United States10 websites



Poland412 websites
Czech Republic76 websites
France24 websites
Hungary19 websites
Germany19 websites
Netherlands14 websites
Slovakia14 websites
Romania7 websites
GB4 websites

Website Distribution by TLD

Number of websites using CVE-2026-41874
.pl295 websites
.com80 websites
.cz58 websites
.eu35 websites
.de17 websites
.net16 websites
.nl14 websites
.org3 websites
.dk3 websites
.ru3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-41874

Top websites that are affected by CVE-2026-41874. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.***.pl Poland***,***
*****.************.pl Poland***,***
****.************.org Poland***,***
************.com Poland***,***
************.de Germany***,***
***********.hu Hungary*,***,***
**************.cz Czech Republic*,***,***
*******.cz Czech Republic*,***,***
********.cz Czech Republic*,***,***
********************.cz Czech Republic*,***,***
See full domain list

FAQ

CVE-2026-41874 is Plaintext Storage of a Password in Quick.Cart
A total of 640 websites have been identified as vulnerable to CVE-2026-41874, based on global website indexing conducted by WebTechSurvey.
The Quick.Cart is affected by the CVE-2026-41874 vulnerability.
Quick.Cart versions up to and including 6.7 are vulnerable to CVE-2026-41874.