Skip to content
COOEY

FAIL › dossier

qcubed

VENDOR

Dossier not yet built — the RAG curator builds one for players with ≥2 failure events. The failure history and sentiment below are live.
FAILURE HISTORY · 4
DATEEVENTSEVSUMMARY
2021-03-04 CVE-2020-24914 critical A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to execute code via a crafted POST request.
2021-03-04 CVE-2020-24914 critical A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to execute code via a crafted POST request.
2021-03-04 CVE-2020-24913 critical A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.
2021-03-04 CVE-2020-24913 critical A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.80
Widely condemned due to unauthenticated RCE in all versions
synthesissevere-fallout-0.80
Widely condemned for critical SQL injection flaw in all versions
cooey ↗severe-fallout-0.90
Critical vulnerability disclosed
"A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request."
www.cvefind.com ↗severe-fallout-0.50
Listed as critical vulnerability
"CVE 2020-24913 is a critical vulnerability in qcubed."
BleepingComputer ↗severe-fallout-0.70
Exploited by hackers
"Hackers exploit Roundcube flaw to spy on academic researchers"
dailysecurityreview.com ↗severe-fallout-0.80
Critical RCE flaw exposed 84,000 servers
"Over 84,000 Roundcube webmail servers remain exposed to a critical RCE flaw (CVE-2025-49113) despite a June 2025 patch fixing the vulnerability."
BleepingComputer ↗severe-fallout-0.60
AI agent vulnerability disclosed
"'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets"
x.com ↗severe-fallout-0.90
Apple accuses OpenAI employee of hacking
"BREAKING: Apple accuses an OpenAI employee of hacking its systems, downloading unreleased product files, & celebrating the breach as 'so funny.'"
www.hipaajournal.com ↗severe-fallout-0.80
Accenture confirms intrusion after hacker claims 35GB data breach
"Accenture Confirms Intrusion After Hacker Claims 35GB Data Breach"
cooey ↗severe-fallout-0.90
Damning disclosure of unauthenticated RCE in all versions
"A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to execute code via a crafted POST request."
www.cvefind.com ↗severe-fallout-0.50
Neutral listing of vulnerability in database
app.opencve.io ↗severe-fallout-0.50
Neutral listing of vulnerability in database
Irrelevant content unrelated to qcubed
www.techradar.com ↗severe-fallout+0.00
Irrelevant content unrelated to qcubed
www.pcworld.com ↗severe-fallout+0.00
Irrelevant content unrelated to qcubed
classactionu.org ↗severe-fallout+0.00
Irrelevant content unrelated to qcubed