Show filters
5,504 Total Results
Displaying 401-410 of 5,504
Sort by:
Attacker Value
Unknown
CVE-2023-49337
Disclosure Date: February 29, 2024 (last updated February 26, 2025)
Concrete CMS before 9.2.3 allows Stored XSS on the Admin Dashboard via /dashboard/system/basics/name. (8.5 and earlier are unaffected.)
0
Attacker Value
Unknown
CVE-2023-48653
Disclosure Date: February 29, 2024 (last updated February 26, 2025)
Concrete CMS before 8.5.14 and 9 before 9.2.3 allows Cross Site Request Forgery (CSRF) via ccm/calendar/dialogs/event/delete/submit. An attacker can force an admin to delete events on the site because the event ID is numeric and sequential.
0
Attacker Value
Unknown
CVE-2023-48651
Disclosure Date: February 29, 2024 (last updated February 26, 2025)
Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) at /ccm/system/dialogs/file/delete/1/submit.
0
Attacker Value
Unknown
CVE-2023-48650
Disclosure Date: February 29, 2024 (last updated February 26, 2025)
Concrete CMS before 8.5.14 and 9 before 9.2.3 is vulnerable to an admin adding a stored XSS payload via the Layout Preset name.
0
Attacker Value
Unknown
CVE-2024-25422
Disclosure Date: February 28, 2024 (last updated February 26, 2025)
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMCMS_Menu.php component.
0
Attacker Value
Unknown
CVE-2024-1925
Disclosure Date: February 27, 2024 (last updated February 26, 2025)
A vulnerability was found in Ctcms 2.1.2. It has been declared as critical. This vulnerability affects unknown code of the file ctcms/apps/controllers/admin/Upsys.php. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254860.
0
Attacker Value
Unknown
CVE-2024-26128
Disclosure Date: February 22, 2024 (last updated February 26, 2025)
baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the content management feature. Version 5.0.9 contains a fix for this vulnerability.
0
Attacker Value
Unknown
CVE-2023-51450
Disclosure Date: February 22, 2024 (last updated February 26, 2025)
baserCMS is a website development framework. Prior to version 5.0.9, there is an OS Command Injection vulnerability in the site search feature of baserCMS. Version 5.0.9 contains a fix for this vulnerability.
0
Attacker Value
Unknown
CVE-2023-44379
Disclosure Date: February 22, 2024 (last updated February 26, 2025)
baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the site search feature. Version 5.0.9 contains a fix for this vulnerability.
0
Attacker Value
Unknown
CVE-2024-25414
Disclosure Date: February 16, 2024 (last updated February 26, 2025)
An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code via uploading a crafted Zip file.
0