CVE-2026-63303

Path Traversal in Quick.CMS

A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolving and serving the requested file. An authenticated attacker with admin privileges can use this vulnerability to read contents of files located in the sibling directory of the webroot via a crafted HTTP request containing ../ sequences in the URI. The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.


We have discovered 1,406 live websites that are affected by CVE-2026-63303.

Run a Free Instant Scan




Affected Software

Product  Quick.CMS
Category Content Management System
Vulnerable Domains1,406 live websites (100% of Quick.CMS install base)
Vulnerable Versions
  • from 0 through 6.8
Vulnerable Versions Count15 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-23 Relative Path Traversal



Details

  • Published - Jul 28, 2026
  • Updated - Jul 28, 2026

Credits

  • Karol Czubernat (finder)

Website Distribution by Country

Number of websites using CVE-2026-63303
United States12 websites



Poland1,189 websites
Czech Republic50 websites
Slovakia25 websites
Germany22 websites
France21 websites
Hungary19 websites
GB6 websites
Denmark5 websites
Romania5 websites

Website Distribution by TLD

Number of websites using CVE-2026-63303
.pl825 websites
.com114 websites
.eu102 websites
.cz38 websites
.net24 websites
.de17 websites
.org14 websites
.info14 websites
.fi5 websites
.ch4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-63303

Top websites that are affected by CVE-2026-63303. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.pl Poland***,***
*******.pl Poland***,***
**********.eu Poland***,***
**********.net Poland***,***
*****.net Poland***,***
******.net Poland***,***
**********.org Poland***,***
*****.pl Poland***,***
******.pl Poland***,***
********.*****.pl Poland***,***
See full domain list

FAQ

CVE-2026-63303 is Relative Path Traversal in Quick.CMS
A total of 1,406 websites have been identified as vulnerable to CVE-2026-63303, based on global website indexing conducted by WebTechSurvey.
The Quick.CMS is affected by the CVE-2026-63303 vulnerability.
Quick.CMS versions up to and including 6.8 are vulnerable to CVE-2026-63303.