Vulnerability index

Browse CVEs

107 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Concrete Cms MEDIUM 5.4
CVE-2022-43687

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 does not issue a new session ID upon successful OAuth authentication. Reme…

Fix: 8.5.10+
Fix from $1,600 2022-11-14
Concrete Cms MEDIUM 6.5
CVE-2022-43686

In Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2, the authTypeConcreteCookieMap table can be filled up causing a denial …

Fix: 8.5.10+
Fix from $1,600 2022-11-14
Concrete Cms MEDIUM 6.1
CVE-2022-43967

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the multilingual report due to un-saniti…

Fix: 8.5.10+
Fix from $1,600 2022-11-14
Concrete Cms MEDIUM 6.1
CVE-2022-43968

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the dashboard icons due to un-sanitized …

Fix: 8.5.10+
Fix from $1,600 2022-11-14
Concrete Cms MEDIUM 6.1
CVE-2022-43694

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the image manipulation library due to un…

Fix: 8.5.10+
Fix from $1,600 2022-11-14
Concrete Cms MEDIUM 6.1
CVE-2022-43692

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS - user can cause an administrator to trigge…

Fix: 8.5.10+
Fix from $1,600 2022-11-14
Concrete Cms HIGH 8.8
CVE-2022-43693

Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for users of Concrete who use th…

Fix: 8.5.10+
Fix from $1,950 2022-11-14
Concrete Cms MEDIUM 6.1
CVE-2022-30120

XSS in /dashboard/blocks/stacks/view_details/ - old browsers only. When using an older browser with built-in XSS protection disabled, insufficient sa…

Fix: 8.5.8 / 9.1.0+
Fix from $1,600 2022-06-24
Concrete Cms CRITICAL 9.8
CVE-2022-21829

Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which could lead…

Fix: 8.5.8 / 9.1.0+
Fix from $2,300 2022-06-24
Concrete Cms CRITICAL 9.1
CVE-2022-30117

Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 allow traversal in /index.php/ccm/system/file/upload which could result in an Arbitrar…

Fix: 8.5.8 / 9.1.0+
Fix from $2,300 2022-06-24
Concrete Cms MEDIUM 6.1
CVE-2022-30118

Title for CVE: XSS in /dashboard/system/express/entities/forms/save_control/[GUID]: old browsers only.Description: When using Internet Explorer with …

Fix: 8.5.8 / 9.1.0+
Fix from $1,600 2022-06-24
Concrete Cms MEDIUM 6.1
CVE-2022-30119

XSS in /dashboard/reports/logs/view - old browsers only. When using Internet Explorer with the XSS protection disabled, insufficient sanitation where…

Fix: 8.5.8 / 9.1.0+
Fix from $1,600 2022-06-24
Concrete Cms HIGH 8.8
CVE-2021-22954

A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an attacker to make requests on behalf of other users.

Fix: 9.0+
Fix from $1,950 2022-02-09
Concrete Cms HIGH 7.2
CVE-2021-40101

An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.

Fix: 8.5.7+
Fix from $1,950 2021-11-30
Concrete Cms HIGH 8.8
CVE-2021-22966

Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below. If a group is granted "view" permissions on the bulk…

Fix: 8.5.7+
Fix from $1,950 2021-11-19
Concrete Cms HIGH 7.5
CVE-2021-22951

Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.7. Concre…

Fix: 8.5.7+
Fix from $1,950 2021-11-19
Concrete Cms HIGH 7.5
CVE-2021-22967

In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to a Convers…

Fix: 8.5.7+
Fix from $1,950 2021-11-19
Concrete Cms HIGH 7.5
CVE-2021-22970

Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system to be vulnerable toa. SSRF a…

Fix: after 8.5.6
Fix from $1,950 2021-11-19
Concrete Cms HIGH 7.2
CVE-2021-22968

A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Concrete CMS (concrete5) versio…

Fix: 8.5.7+
Fix from $1,950 2021-11-19
Concrete Cms MEDIUM 5.3
CVE-2021-22969

Concrete CMS (formerly concrete5) versions below 8.5.7 has a SSRF mitigation bypass using DNS Rebind attack giving an attacker the ability to fetch c…

Fix: 8.5.7+
Fix from $1,600 2021-11-19
Concrete Cms CRITICAL 9.8
CVE-2021-22958

A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the limitatio…

Fix: 8.5.5+
Fix from $2,300 2021-10-07
Concrete Cms HIGH 8.8
CVE-2021-40108

An issue was discovered in Concrete CMS through 8.5.5. The Calendar is vulnerable to CSRF. ccm_token is not verified on the ccm/calendar/dialogs/even…

Fix: 8.5.6+
Fix from $1,950 2021-09-27
Concrete Cms MEDIUM 6.4
CVE-2021-40109

A SSRF issue was discovered in Concrete CMS through 8.5.5. Users can access forbidden files on their local network. A user with permissions to upload…

Fix: 8.5.6+
Fix from $1,600 2021-09-27
Concrete Cms CRITICAL 9.8
CVE-2021-40098

An issue was discovered in Concrete CMS through 8.5.5. Path Traversal leading to RCE via external form by adding a regular expression.

Fix: after 8.5.5
Fix from $2,300 2021-09-27
Concrete Cms HIGH 7.5
CVE-2021-40103

An issue was discovered in Concrete CMS through 8.5.5. Path Traversal can lead to Arbitrary File Reading and SSRF.

Fix: after 8.5.5
Fix from $1,950 2021-09-27
Concrete Cms HIGH 7.5
CVE-2021-40104

An issue was discovered in Concrete CMS through 8.5.5. There is an SVG sanitizer bypass.

Fix: after 8.5.5
Fix from $1,950 2021-09-27
Concrete Cms MEDIUM 6.1
CVE-2021-40105

An issue was discovered in Concrete CMS through 8.5.5. There is XSS via Markdown Comments.

Fix: after 8.5.5
Fix from $1,600 2021-09-27
Concrete Cms MEDIUM 6.1
CVE-2021-40106

An issue was discovered in Concrete CMS through 8.5.5. There is unauthenticated stored XSS in blog comments via the website field.

Fix: after 8.5.5
Fix from $1,600 2021-09-27
Concrete Cms HIGH 8.8
CVE-2021-40097

An issue was discovered in Concrete CMS through 8.5.5. Authenticated path traversal leads to to remote code execution via uploaded PHP code, related …

Fix: after 8.5.5
Fix from $1,950 2021-09-27
Concrete Cms CRITICAL 9.1
CVE-2021-40102

An issue was discovered in Concrete CMS through 8.5.5. Arbitrary File deletion can occur via PHAR deserialization in is_dir (PHP Object Injection ass…

Fix: after 8.5.5
Fix from $2,300 2021-09-24