VulnerabilityAnalyzed
CVE-2026-23797
An attacker with high privileges can display users' password in user editing page.
MEDIUM 6.9EPSS 0.26%
Does this matter?
Lower severity and a low EPSS score (0.26%). Track it; it rarely justifies an emergency change on its own.
Description
In Quick.Cart user passwords are stored in plaintext form. An attacker with high privileges can display users' password in user editing page. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.7 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
- CVSS 4.0
- 6.9 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.26% probability · 17th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-256
- Affected
- opensolution/quick.cart
- Source
- cvd@cert.pl
References
- https://cert.pl/posts/2026/02/CVE-2026-23796Third Party Advisory
- https://opensolution.org/sklep-internetowy-quick-cart.htmlProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.