Quick Index (quickindex) 5.0.0 to below 5.0.5 - Authenticated Stored XSS via Crafted Index Class Options
Regular Labs Quick Index 5.0.0 through 5.0.4 is affected by CVE-2026-85190, fixed in 5.0.5 (released 13 September 2026). Crafted index class options were not sanitised, allowing JavaScript to be injected into the rendered index. Exploitation requires the ability to author or edit content containing a Quick Index tag, so this is an authenticated stored XSS. Update to 5.0.5 or later. The same release also fixes indexes showing headings from articles the visitor cannot access, an access control defect the vendor did not label a security fix but which discloses restricted article titles to unauthorised visitors. The CVE record was published on 14 September 2026 with a CVSS 4.0 base score of 7.5 (High), vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/S:N/AU:N.
Affected versions: ≥ 5.0.0 and < 5.0.5
Full advisory: regularlabs.com