Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Concrete Cms MEDIUM 6.5
CVE-2026-30662

ConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. The 'download' method in 'concrete/controllers/bac…

No fix yet
Fix from $1,600 2026-03-24
Concrete Cms MEDIUM 5.4
CVE-2023-44763

Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cross-Site Scripting (XSS). NOTE:…

No fix yet
Fix from $1,600 2023-10-10
Concrete Cms MEDIUM 5.4
CVE-2023-44761

Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS versions affected to 8.5.13 and below, and 9.0.0 through 9.2.1 allow a local atta…

No fix yet
Fix from $1,600 2023-10-06
Concrete Cms MEDIUM 5.4
CVE-2023-44762

A Cross Site Scripting (XSS) vulnerability in Concrete CMS from versions 9.2.0 to 9.2.2 allows an attacker to execute arbitrary code via a crafted sc…

No fix yet
Fix from $1,600 2023-10-06
Concrete Cms MEDIUM 5.4
CVE-2023-44764

A Cross Site Scripting (XSS) vulnerability in Concrete CMS before 9.2.3 exists via the Name parameter during installation (aka Site of Installation o…

No fix yet
Fix from $1,600 2023-10-06
Concrete Cms MEDIUM 5.4
CVE-2023-44765

A Cross Site Scripting (XSS) vulnerability in Concrete CMS versions 8.5.12 and below, and 9.0 through 9.2.1 allows an attacker to execute arbitrary c…

No fix yet
Fix from $1,600 2023-10-06
Concrete Cms HIGH 7.2
CVE-2018-13790

A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network an…

No fix yet
Fix from $1,950 2018-07-09
Concrete Cms HIGH 8.8
CVE-2015-4724

SQL injection vulnerability in Concrete5 5.7.3.1.

No fix yet
Fix from $1,950 2017-09-07
Concrete Cms MEDIUM 6.1
CVE-2015-4721

Multiple cross-site scripting (XSS) vulnerabilities in Concrete5 5.7.3.1.

No fix yet
Fix from $1,600 2017-09-07
Concrete Cms MEDIUM 6.5
CVE-2017-8082

concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking…

No fix yet
Fix from $1,600 2017-04-24
Concrete Cms MEDIUM 6.1
CVE-2017-7725

concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "canonical" URL on installation …

No fix yet
Fix from $1,600 2017-04-13