Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-30662 ConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. The 'download' method in 'concrete/controllers/bac… Concrete Cms No fix yet Fix from $1,6002026-03-24 MEDIUM 5.4 CVE-2023-44763 Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cross-Site Scripting (XSS). NOTE:… Concrete Cms No fix yet Fix from $1,6002023-10-10 MEDIUM 5.4 CVE-2023-44761 Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS versions affected to 8.5.13 and below, and 9.0.0 through 9.2.1 allow a local atta… Concrete Cms No fix yet Fix from $1,6002023-10-06 MEDIUM 5.4 CVE-2023-44762 A Cross Site Scripting (XSS) vulnerability in Concrete CMS from versions 9.2.0 to 9.2.2 allows an attacker to execute arbitrary code via a crafted sc… Concrete Cms No fix yet Fix from $1,6002023-10-06 MEDIUM 5.4 CVE-2023-44764 A Cross Site Scripting (XSS) vulnerability in Concrete CMS before 9.2.3 exists via the Name parameter during installation (aka Site of Installation o… Concrete Cms No fix yet Fix from $1,6002023-10-06 MEDIUM 5.4 CVE-2023-44765 A Cross Site Scripting (XSS) vulnerability in Concrete CMS versions 8.5.12 and below, and 9.0 through 9.2.1 allows an attacker to execute arbitrary c… Concrete Cms No fix yet Fix from $1,6002023-10-06 HIGH 7.2 CVE-2018-13790 A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network an… Concrete Cms No fix yet Fix from $1,9502018-07-09 HIGH 8.8 CVE-2015-4724 SQL injection vulnerability in Concrete5 5.7.3.1. Concrete Cms No fix yet Fix from $1,9502017-09-07 MEDIUM 6.1 CVE-2015-4721 Multiple cross-site scripting (XSS) vulnerabilities in Concrete5 5.7.3.1. Concrete Cms No fix yet Fix from $1,6002017-09-07 MEDIUM 6.5 CVE-2017-8082 concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking… Concrete Cms No fix yet Fix from $1,6002017-04-24 MEDIUM 6.1 CVE-2017-7725 concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "canonical" URL on installation … Concrete Cms No fix yet Fix from $1,6002017-04-13