Show filters
99 Total Results
Displaying 31-40 of 99
Sort by:
Attacker Value
Unknown
CVE-2023-44761
Disclosure Date: October 06, 2023 (last updated December 07, 2023)
Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS versions affected to 8.5.13 and below, and 9.0.0 through 9.2.1 allow a local attacker to execute arbitrary code via a crafted script to the Forms of the Data objects.
0
Attacker Value
Unknown
CVE-2023-28821
Disclosure Date: April 28, 2023 (last updated October 08, 2023)
Concrete CMS (previously concrete5) before 9.1 did not have a rate limit for password resets.
0
Attacker Value
Unknown
CVE-2023-28820
Disclosure Date: April 28, 2023 (last updated October 08, 2023)
Concrete CMS (previously concrete5) before 9.1 is vulnerable to stored XSS in RSS Displayer via the href attribute because the link element input was not sanitized.
0
Attacker Value
Unknown
CVE-2023-28819
Disclosure Date: April 28, 2023 (last updated December 06, 2023)
Concrete CMS (previously concrete5) versions 8.5.12 and below, 9.0.0 through 9.0.2 is vulnerable to Stored XSS in uploaded file and folder names.
0
Attacker Value
Unknown
CVE-2023-28477
Disclosure Date: April 28, 2023 (last updated December 06, 2023)
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to stored XSS on API Integrations via the name parameter.
0
Attacker Value
Unknown
CVE-2023-28476
Disclosure Date: April 28, 2023 (last updated January 09, 2024)
Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Tags on uploaded files.
0
Attacker Value
Unknown
CVE-2023-28475
Disclosure Date: April 28, 2023 (last updated December 06, 2023)
Concrete CMS (previously concrete5) versions 8.5.12 and below, and versions 9.0 through 9.1.3 is vulnerable to Reflected XSS on the Reply form because msgID was not sanitized.
0
Attacker Value
Unknown
CVE-2023-28474
Disclosure Date: April 28, 2023 (last updated January 09, 2024)
Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Saved Presets on search.
0
Attacker Value
Unknown
CVE-2023-28473
Disclosure Date: April 28, 2023 (last updated December 06, 2023)
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to possible Auth bypass in the jobs section.
0
Attacker Value
Unknown
CVE-2023-28472
Disclosure Date: April 28, 2023 (last updated December 06, 2023)
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 does not have Secure and HTTP only attributes set for ccmPoll cookies.
0