Show filters
182 Total Results
Displaying 101-110 of 182
Sort by:
Attacker Value
Unknown

CVE-2021-40097

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
An issue was discovered in Concrete CMS through 8.5.5. Authenticated path traversal leads to to remote code execution via uploaded PHP code, related to the bFilename parameter.
Attacker Value
Unknown

CVE-2021-40106

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
An issue was discovered in Concrete CMS through 8.5.5. There is unauthenticated stored XSS in blog comments via the website field.
Attacker Value
Unknown

CVE-2021-40104

Disclosure Date: September 27, 2021 (last updated November 28, 2024)
An issue was discovered in Concrete CMS through 8.5.5. There is an SVG sanitizer bypass.
Attacker Value
Unknown

CVE-2021-40105

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
An issue was discovered in Concrete CMS through 8.5.5. There is XSS via Markdown Comments.
Attacker Value
Unknown

CVE-2021-40103

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
An issue was discovered in Concrete CMS through 8.5.5. Path Traversal can lead to Arbitrary File Reading and SSRF.
Attacker Value
Unknown

CVE-2021-40098

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
An issue was discovered in Concrete CMS through 8.5.5. Path Traversal leading to RCE via external form by adding a regular expression.
Attacker Value
Unknown

CVE-2021-40099

Disclosure Date: September 24, 2021 (last updated November 28, 2024)
An issue was discovered in Concrete CMS through 8.5.5. Fetching the update json scheme over HTTP leads to remote code execution.
Attacker Value
Unknown

CVE-2021-40102

Disclosure Date: September 24, 2021 (last updated February 23, 2025)
An issue was discovered in Concrete CMS through 8.5.5. Arbitrary File deletion can occur via PHAR deserialization in is_dir (PHP Object Injection associated with the __wakeup magic method).
Attacker Value
Unknown

CVE-2021-40100

Disclosure Date: September 24, 2021 (last updated February 23, 2025)
An issue was discovered in Concrete CMS through 8.5.5. Stored XSS can occur in Conversations when the Active Conversation Editor is set to Rich Text.
Attacker Value
Unknown

CVE-2021-22949

Disclosure Date: September 23, 2021 (last updated February 23, 2025)
A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security CMS Research Team"