Show filters
99 Total Results
Displaying 31-40 of 99
Sort by:
Attacker Value
Unknown

CVE-2023-44761

Disclosure Date: October 06, 2023 (last updated December 07, 2023)
Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS versions affected to 8.5.13 and below, and 9.0.0 through 9.2.1 allow a local attacker to execute arbitrary code via a crafted script to the Forms of the Data objects.
Attacker Value
Unknown

CVE-2023-28821

Disclosure Date: April 28, 2023 (last updated October 08, 2023)
Concrete CMS (previously concrete5) before 9.1 did not have a rate limit for password resets.
Attacker Value
Unknown

CVE-2023-28820

Disclosure Date: April 28, 2023 (last updated October 08, 2023)
Concrete CMS (previously concrete5) before 9.1 is vulnerable to stored XSS in RSS Displayer via the href attribute because the link element input was not sanitized.
Attacker Value
Unknown

CVE-2023-28819

Disclosure Date: April 28, 2023 (last updated December 06, 2023)
Concrete CMS (previously concrete5) versions 8.5.12 and below, 9.0.0 through 9.0.2 is vulnerable to Stored XSS in uploaded file and folder names.
Attacker Value
Unknown

CVE-2023-28477

Disclosure Date: April 28, 2023 (last updated December 06, 2023)
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to stored XSS on API Integrations via the name parameter.
Attacker Value
Unknown

CVE-2023-28476

Disclosure Date: April 28, 2023 (last updated January 09, 2024)
Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Tags on uploaded files.
Attacker Value
Unknown

CVE-2023-28475

Disclosure Date: April 28, 2023 (last updated December 06, 2023)
Concrete CMS (previously concrete5) versions 8.5.12 and below, and versions 9.0 through 9.1.3 is vulnerable to Reflected XSS on the Reply form because msgID was not sanitized.
Attacker Value
Unknown

CVE-2023-28474

Disclosure Date: April 28, 2023 (last updated January 09, 2024)
Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Saved Presets on search.
Attacker Value
Unknown

CVE-2023-28473

Disclosure Date: April 28, 2023 (last updated December 06, 2023)
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to possible Auth bypass in the jobs section.
Attacker Value
Unknown

CVE-2023-28472

Disclosure Date: April 28, 2023 (last updated December 06, 2023)
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 does not have Secure and HTTP only attributes set for ccmPoll cookies.