CVE-2026-63301

Denial of Service in Quick.CMS

In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; however, the underlying language-deletion API endpoint does not enforce an equivalent server-side authorization check. As a result, an authenticated administrator can bypass the UI-level restriction and delete the primary language by sending a direct HTTP request to the API endpoint. Successful deletion of the primary language results in a Denial of Service (DoS) of application. Critically, when combined with a separate Cross-Site Request Forgery (CSRF) vulnerability (CVE-2026-1468) an unauthenticated remote attacker can craft a malicious link, which if visited by an authenticated administrator, will trigger the DoS condition without direct access to the application The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.


We have discovered 1,406 live websites that are affected by CVE-2026-63301.

Run a Free Instant Scan




Affected Software

Product  Quick.CMS
Category Content Management System
Vulnerable Domains1,406 live websites (100% of Quick.CMS install base)
Vulnerable Versions
  • from 0 through 6.8
Vulnerable Versions Count15 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-602 Client-Side Enforcement of Server-Side Security



Details

  • Published - Jul 28, 2026
  • Updated - Jul 28, 2026

Credits

  • Karol Czubernat (finder)

Website Distribution by Country

Number of websites using CVE-2026-63301
United States12 websites



Poland1,189 websites
Czech Republic50 websites
Slovakia25 websites
Germany22 websites
France21 websites
Hungary19 websites
GB6 websites
Denmark5 websites
Romania5 websites

Website Distribution by TLD

Number of websites using CVE-2026-63301
.pl825 websites
.com114 websites
.eu102 websites
.cz38 websites
.net24 websites
.de17 websites
.org14 websites
.info14 websites
.fi5 websites
.ch4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-63301

Top websites that are affected by CVE-2026-63301. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.pl Poland***,***
*******.pl Poland***,***
**********.eu Poland***,***
**********.net Poland***,***
*****.net Poland***,***
******.net Poland***,***
**********.org Poland***,***
*****.pl Poland***,***
******.pl Poland***,***
********.*****.pl Poland***,***
See full domain list

FAQ

CVE-2026-63301 is Client-Side Enforcement of Server-Side Security in Quick.CMS
A total of 1,406 websites have been identified as vulnerable to CVE-2026-63301, based on global website indexing conducted by WebTechSurvey.
The Quick.CMS is affected by the CVE-2026-63301 vulnerability.
Quick.CMS versions up to and including 6.8 are vulnerable to CVE-2026-63301.