VYPR

Concrete5

by Concrete5

Source repositories

CVEs (166)

  • CVE-2023-48653MedFeb 29, 2024
    risk 0.21cvss 4.3epss 0.00

    Concrete CMS before 8.5.14 and 9 before 9.2.3 allows Cross Site Request Forgery (CSRF) via ccm/calendar/dialogs/event/delete/submit. An attacker can force an admin to delete events on the site because the event ID is numeric and sequential.

  • CVE-2023-48651MedFeb 29, 2024
    risk 0.21cvss 4.3epss 0.00

    Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) at /ccm/system/dialogs/file/delete/1/submit.

  • CVE-2023-48649LowNov 17, 2023
    risk 0.16cvss 3.5epss 0.01

    Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows stored XSS on the Admin page via an uploaded file name.

  • CVE-2023-28819LowApr 28, 2023
    risk 0.16cvss 3.5epss 0.01

    Concrete CMS (previously concrete5) versions 8.5.12 and below, 9.0.0 through 9.0.2 is vulnerable to Stored XSS in uploaded file and folder names.

  • CVE-2023-28473LowApr 28, 2023
    risk 0.15cvss 3.3epss 0.01

    Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to possible Auth bypass in the jobs section.

  • CVE-2024-3181LowApr 3, 2024
    risk 0.13cvss 3.1epss 0.00

    Concrete CMS version 9 prior to 9.2.8 and previous versions prior to 8.5.16 are vulnerable to Stored XSS in the Search Field. Prior to the fix, stored XSS could be executed by an administrator changing a filter to which a rogue administrator had previously added malicious…

  • CVE-2024-3180LowApr 3, 2024
    risk 0.13cvss 3.1epss 0.00

    Concrete CMS version 9 below 9.2.8 and previous versions below 8.5.16 is vulnerable to Stored XSS in blocks of type file. Stored XSS could be caused by a rogue administrator adding malicious code to the link-text field when creating a block of type file. The Concrete CMS…

  • CVE-2024-3179LowApr 3, 2024
    risk 0.13cvss 3.1epss 0.00

    Concrete CMS version 9 before 9.2.8 and previous versions before 8.5.16 are vulnerable to Stored XSS in the Custom Class page editing. Prior to the fix, a rogue administrator could insert malicious code in the custom class field due to insufficient validation of administrator…

  • CVE-2024-3178LowApr 3, 2024
    risk 0.13cvss 3.1epss 0.00

    Concrete CMS versions 9 below 9.2.8 and versions below 8.5.16 are vulnerable to Cross-site Scripting (XSS) in the Advanced File Search Filter. Prior to the fix, a rogue administrator could add malicious code in the file manager because of insufficient validation of…

  • CVE-2023-49337LowFeb 29, 2024
    risk 0.09cvss 2.4epss 0.01

    Concrete CMS before 9.2.3 allows Stored XSS on the Admin Dashboard via /dashboard/system/basics/name. (8.5 and earlier are unaffected.)

  • CVE-2024-1245LowFeb 9, 2024
    risk 0.09cvss 2.4epss 0.00

    Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributes since administrator entered file attributes are not sufficiently sanitized in the Edit Attributes page. A rogue administrator could put malicious code into the file tags or…

  • CVE-2024-2179LowMar 5, 2024
    risk 0.07cvss 2.2epss 0.00

    Concrete CMS version 9 before 9.2.7 is vulnerable to Stored XSS via the Name field of a Group type since there is insufficient validation of administrator provided data for that field. A rogue administrator could inject malicious code into the Name field which might be executed…

  • CVE-2024-2753LowApr 3, 2024
    risk 0.06cvss 2.0epss 0.00

    Concrete CMS version 9 before 9.2.8 and previous versions prior to 8.5.16 is vulnerable to Stored XSS on the calendar color settings screen since Information input by the user is output without escaping. A rogue administrator could inject malicious javascript into the Calendar…

  • CVE-2024-1246LowFeb 9, 2024
    risk 0.06cvss 2.0epss 0.00

    Concrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import Feature due to insufficient validation of administrator provided data. A rogue administrator could inject malicious code when importing images, leading to the execution of the…

  • CVE-2024-1247LowFeb 9, 2024
    risk 0.06cvss 2.0epss 0.01

    Concrete CMS version 9 before 9.2.5 is vulnerable to  stored XSS via the Role Name field since there is insufficient validation of administrator provided data for that field. A rogue administrator could inject malicious code into the Role Name field which might be executed…

  • CVE-2023-28820LowApr 28, 2023
    risk 0.06cvss 2.0epss 0.00

    Concrete CMS (previously concrete5) before 9.1 is vulnerable to stored XSS in RSS Displayer via the href attribute because the link element input was not sanitized.

  • CVE-2017-18195MedFeb 26, 2018
    risk 0.04cvss 5.3epss 0.11

    An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. An unauthenticated user can enumerate comments from all blog posts by POSTing requests to /index.php/tools/required/conversations/view_ajax with incremental 'cnvID' integers.

  • CVE-2021-22958CriOct 7, 2021
    risk 0.00cvss 9.8epss 0.01

    A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the limitations in place for localhost allowing interaction with local services. Impact can vary depending on services exposed.CVSSv2.0…

  • CVE-2020-14961MedJun 22, 2020
    risk 0.00cvss 5.3epss 0.01

    Concrete5 before 8.5.3 does not constrain the sort direction to a valid asc or desc value.

  • CVE-2015-3989May 15, 2015
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in concrete5 before 5.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to private messages or other unspecified vectors.

Page 8 of 9