CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-63303

unknowncovered by 1 sourcefirst seen 2026-07-28
A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolving and serving the requested file. An authenticated attacker with admin privileges can use this vulnerability to read contents of files located in the sibling directory of the webroot via a crafted HTTP request containing ../ sequences in the URI. The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.

⚡ Watch CVE-2026-63303

Get an email if CVE-2026-63303 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-63303

CVE.org record

Embed the live status

CVE-2026-63303 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-63303 status](https://www.csirts.com/badge/CVE-2026-63303)](https://www.csirts.com/cve/CVE-2026-63303)