Show filters
5,504 Total Results
Displaying 401-410 of 5,504
Sort by:
Attacker Value
Unknown

CVE-2023-49337

Disclosure Date: February 29, 2024 (last updated February 26, 2025)
Concrete CMS before 9.2.3 allows Stored XSS on the Admin Dashboard via /dashboard/system/basics/name. (8.5 and earlier are unaffected.)
Attacker Value
Unknown

CVE-2023-48653

Disclosure Date: February 29, 2024 (last updated February 26, 2025)
Concrete CMS before 8.5.14 and 9 before 9.2.3 allows Cross Site Request Forgery (CSRF) via ccm/calendar/dialogs/event/delete/submit. An attacker can force an admin to delete events on the site because the event ID is numeric and sequential.
Attacker Value
Unknown

CVE-2023-48651

Disclosure Date: February 29, 2024 (last updated February 26, 2025)
Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) at /ccm/system/dialogs/file/delete/1/submit.
Attacker Value
Unknown

CVE-2023-48650

Disclosure Date: February 29, 2024 (last updated February 26, 2025)
Concrete CMS before 8.5.14 and 9 before 9.2.3 is vulnerable to an admin adding a stored XSS payload via the Layout Preset name.
Attacker Value
Unknown

CVE-2024-25422

Disclosure Date: February 28, 2024 (last updated February 26, 2025)
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMCMS_Menu.php component.
Attacker Value
Unknown

CVE-2024-1925

Disclosure Date: February 27, 2024 (last updated February 26, 2025)
A vulnerability was found in Ctcms 2.1.2. It has been declared as critical. This vulnerability affects unknown code of the file ctcms/apps/controllers/admin/Upsys.php. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254860.
Attacker Value
Unknown

CVE-2024-26128

Disclosure Date: February 22, 2024 (last updated February 26, 2025)
baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the content management feature. Version 5.0.9 contains a fix for this vulnerability.
Attacker Value
Unknown

CVE-2023-51450

Disclosure Date: February 22, 2024 (last updated February 26, 2025)
baserCMS is a website development framework. Prior to version 5.0.9, there is an OS Command Injection vulnerability in the site search feature of baserCMS. Version 5.0.9 contains a fix for this vulnerability.
Attacker Value
Unknown

CVE-2023-44379

Disclosure Date: February 22, 2024 (last updated February 26, 2025)
baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the site search feature. Version 5.0.9 contains a fix for this vulnerability.
Attacker Value
Unknown

CVE-2024-25414

Disclosure Date: February 16, 2024 (last updated February 26, 2025)
An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code via uploading a crafted Zip file.