CVE-2026-63302

Local File Inclusion in Quick.CMS

Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated attacker with admin privileges can include arbitrary files located within the application's directory structure via a crafted HTTP request. Successful exploitation allows disclosure of the server's directory structure and absolute file paths (path disclosure). The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.


We have discovered 1,406 live websites that are affected by CVE-2026-63302.

Run a Free Instant Scan




Affected Software

Product  Quick.CMS
Category Content Management System
Vulnerable Domains1,406 live websites (100% of Quick.CMS install base)
Vulnerable Versions
  • from 0 through 6.8
Vulnerable Versions Count15 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')



Details

  • Published - Jul 28, 2026
  • Updated - Jul 28, 2026

Credits

  • Karol Czubernat (finder)

Website Distribution by Country

Number of websites using CVE-2026-63302
United States12 websites



Poland1,189 websites
Czech Republic50 websites
Slovakia25 websites
Germany22 websites
France21 websites
Hungary19 websites
GB6 websites
Denmark5 websites
Romania5 websites

Website Distribution by TLD

Number of websites using CVE-2026-63302
.pl825 websites
.com114 websites
.eu102 websites
.cz38 websites
.net24 websites
.de17 websites
.org14 websites
.info14 websites
.fi5 websites
.ch4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-63302

Top websites that are affected by CVE-2026-63302. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.pl Poland***,***
*******.pl Poland***,***
**********.eu Poland***,***
**********.net Poland***,***
*****.net Poland***,***
******.net Poland***,***
**********.org Poland***,***
*****.pl Poland***,***
******.pl Poland***,***
********.*****.pl Poland***,***
See full domain list

FAQ

CVE-2026-63302 is Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') in Quick.CMS
A total of 1,406 websites have been identified as vulnerable to CVE-2026-63302, based on global website indexing conducted by WebTechSurvey.
The Quick.CMS is affected by the CVE-2026-63302 vulnerability.
Quick.CMS versions up to and including 6.8 are vulnerable to CVE-2026-63302.