VYPR

Vendor CVEs

Concrete5

All CVEs

166 total · sorted by risk
  • CVE-2024-1245LowFeb 9, 2024
    risk 0.09cvss 2.4epss 0.00

    Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributes since administrator entered file attributes are not sufficiently sanitized in the Edit Attributes page. A rogue administrator could put malicious code into the file tags or…

  • CVE-2024-2179LowMar 5, 2024
    risk 0.07cvss 2.2epss 0.00

    Concrete CMS version 9 before 9.2.7 is vulnerable to Stored XSS via the Name field of a Group type since there is insufficient validation of administrator provided data for that field. A rogue administrator could inject malicious code into the Name field which might be executed…

  • CVE-2024-2753LowApr 3, 2024
    risk 0.06cvss 2.0epss 0.00

    Concrete CMS version 9 before 9.2.8 and previous versions prior to 8.5.16 is vulnerable to Stored XSS on the calendar color settings screen since Information input by the user is output without escaping. A rogue administrator could inject malicious javascript into the Calendar…

  • CVE-2024-1246LowFeb 9, 2024
    risk 0.06cvss 2.0epss 0.00

    Concrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import Feature due to insufficient validation of administrator provided data. A rogue administrator could inject malicious code when importing images, leading to the execution of the…

  • CVE-2024-1247LowFeb 9, 2024
    risk 0.06cvss 2.0epss 0.01

    Concrete CMS version 9 before 9.2.5 is vulnerable to  stored XSS via the Role Name field since there is insufficient validation of administrator provided data for that field. A rogue administrator could inject malicious code into the Role Name field which might be executed…

  • CVE-2023-28820LowApr 28, 2023
    risk 0.06cvss 2.0epss 0.00

    Concrete CMS (previously concrete5) before 9.1 is vulnerable to stored XSS in RSS Displayer via the href attribute because the link element input was not sanitized.

  • CVE-2017-18195MedFeb 26, 2018
    risk 0.04cvss 5.3epss 0.11

    An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. An unauthenticated user can enumerate comments from all blog posts by POSTing requests to /index.php/tools/required/conversations/view_ajax with incremental 'cnvID' integers.

  • CVE-2021-22958CriOct 7, 2021
    risk 0.00cvss 9.8epss 0.01

    A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the limitations in place for localhost allowing interaction with local services. Impact can vary depending on services exposed.CVSSv2.0…

  • CVE-2020-14961MedJun 22, 2020
    risk 0.00cvss 5.3epss 0.01

    Concrete5 before 8.5.3 does not constrain the sort direction to a valid asc or desc value.

  • CVE-2015-3989May 15, 2015
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in concrete5 before 5.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to private messages or other unspecified vectors.

  • CVE-2015-2250May 15, 2015
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in concrete5 before 5.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) banned_word[] parameter to index.php/dashboard/system/conversations/bannedwords/success, (2) channel parameter to…

  • CVE-2014-9526Jan 5, 2015
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in concrete5 5.7.2.1, 5.7.2, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gName parameter in single_pages/dashboard/users/groups/bulkupdate.php or (2) instance_id parameter in…

  • CVE-2014-5108Jul 28, 2014
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in single_pages\download_file.php in concrete5 before 5.6.3 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to index.php/download_file.

  • CVE-2014-5107Jul 28, 2014
    risk 0.00cvss epss 0.03

    concrete5 before 5.6.3 allows remote attackers to obtain the installation path via a direct request to (1) system/basics/editor.php, (2) system/view.php, (3) system/environment/file_storage_locations.php, (4) system/mail/importers.php, (5) system/mail/method.php, (6)…

  • CVE-2012-5181Dec 21, 2012
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in concrete5 Japanese 5.5.1 through 5.5.2.1 and concrete5 English 5.5.0 through 5.6.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2011-3721Sep 23, 2011
    risk 0.00cvss epss 0.01

    concrete 5.4.0.5, 5.4.1, and 5.4.1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tools/spellchecker_service.php and certain other files.

Page 4 of 4