Qnap Qulog Center vulnerabilities
8 known vulnerabilities affecting qnap/qulog_center.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM4LOW2
Vulnerabilities
Page 1 of 1
CVE-2025-54168LOWCVSS 2.2≥ 1.8.0.872, < 1.8.2.9232025-11-07
CVE-2025-54168 [LOW] CWE-79 CVE-2025-54168: A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If a remote att
A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data.
We have already fixed the vulnerability in the following version:
QuLog Center 1.8.2.923 ( 2025/08/27 ) and later
nvd
CVE-2025-58469LOWCVSS 1.2≥ 1.8.0.872, < 1.8.2.9232025-11-07
CVE-2025-58469 [LOW] CWE-352 CVE-2025-58469: A cross-site request forgery (CSRF) vulnerability has been reported to affect QuLog Center. The remo
A cross-site request forgery (CSRF) vulnerability has been reported to affect QuLog Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities.
We have already fixed the vulnerability in the following version:
QuLog Center 1.8.2.927 ( 2025/09/17 ) and later
nvd
CVE-2024-53696MEDIUMCVSS 5.1≥ 1.7.0, < 1.7.0.829≥ 1.8.0, < 1.8.0.8882025-03-07
CVE-2024-53696 [MEDIUM] CWE-918 CVE-2024-53696: A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If expl
A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read application data.
We have already fixed the vulnerability in the following versions:
QuLog Center 1.7.0.829 ( 2024/10/01 ) and later
QuLog Center 1.8.0
nvd
CVE-2023-23354HIGHCVSS 8.7fixed in 1.5.0.738fixed in 1.3.1.645+1 more2024-12-19
CVE-2023-23354 [HIGH] CWE-79 CVE-2023-23354: A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to bypass security mechanisms or read application data.
We have already fixed the vulnerability in the following versions:
QuLog Center 1.5.0.738 ( 2023/
nvd
CVE-2023-23357MEDIUMCVSS 4.8fixed in 1.5.0.738fixed in 1.3.1.645+1 more2024-12-19
CVE-2023-23357 [MEDIUM] CWE-79 CVE-2023-23357: A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to bypass security mechanisms or read application data.
We have already fixed the vulnerability in the following versions:
QuLog Center 1.5.0.
nvd
CVE-2024-48862HIGHCVSS 8.7≥ 1.7.0.800, < 1.7.0.831≥ 1.8.0.872, < 1.8.0.8882024-11-22
CVE-2024-48862 [HIGH] CWE-59 CVE-2024-48862: A link following vulnerability has been reported to affect QuLog Center. If exploited, the vulnerabi
A link following vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected files.
We have already fixed the vulnerability in the following versions:
QuLog Center 1.7.0.831 ( 2024/10/15 ) and la
nvd
CVE-2024-32762MEDIUMCVSS 6.1≥ 1.7.0, < 1.7.0.827≥ 1.8.0, < 1.8.0.8722024-09-06
CVE-2024-32762 [HIGH] CWE-79 CVE-2024-32762: A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If exploited, t
A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow users to inject malicious code via a network.
We have already fixed the vulnerability in the following versions:
QuLog Center 1.8.0.872 ( 2024/06/17 ) and later
QuLog Center 1.7.0.827 ( 2024/06/17 ) and later
nvd
CVE-2020-36196MEDIUMCVSS 6.1fixed in 1.2.02021-07-01
CVE-2020-36196 [MEDIUM] CWE-80 CVE-2020-36196: A stored XSS vulnerability has been reported to affect QNAP NAS running QuLog Center. If exploited,
A stored XSS vulnerability has been reported to affect QNAP NAS running QuLog Center. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QuLog Center versions prior to 1.2.0.
nvd