Vulnerability index

Browse CVEs

107 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Concrete Cms HIGH 7.2
CVE-2021-40099

An issue was discovered in Concrete CMS through 8.5.5. Fetching the update json scheme over HTTP leads to remote code execution.

Fix: after 8.5.5
Fix from $1,950 2021-09-24
Concrete Cms MEDIUM 5.4
CVE-2021-40100

An issue was discovered in Concrete CMS through 8.5.5. Stored XSS can occur in Conversations when the Active Conversation Editor is set to Rich Text.

Fix: after 8.5.5
Fix from $1,600 2021-09-24
Concrete Cms MEDIUM 5.4
CVE-2021-22953

A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of disk space.Cr…

Fix: after 8.5.5
Fix from $1,600 2021-09-23
Concrete Cms MEDIUM 6.5
CVE-2021-22950

Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for discovery:…

Fix: 8.5.6+
Fix from $1,600 2021-09-23
Concrete Cms MEDIUM 5.4
CVE-2021-22949

A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space…

Fix: after 8.5.5
Fix from $1,600 2021-09-23
Concrete Cms HIGH 7.2
CVE-2021-36766

Concrete5 through 8.5.5 deserializes Untrusted Data. The vulnerable code is located within the controllers/single_page/dashboard/system/environment/l…

Fix: 8.5.6+
Fix from $1,950 2021-07-30
Concrete Cms MEDIUM 5.4
CVE-2021-28145

Concrete CMS (formerly concrete5) before 8.5.5 allows remote authenticated users to conduct XSS attacks via a crafted survey block. This requires at …

Fix: 8.5.5+
Fix from $1,600 2021-03-18
Concrete Cms HIGH 7.2
CVE-2020-24986

Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File Manager. It is possible to mo…

Fix: after 8.5.2
Fix from $1,950 2020-09-04
Concrete Cms HIGH 7.2
CVE-2020-11476

Concrete5 before 8.5.3 allows Unrestricted Upload of File with Dangerous Type such as a .phar file.

Fix: 8.5.3+
Fix from $1,950 2020-07-28
Concrete Cms MEDIUM 5.3
CVE-2020-14961

Concrete5 before 8.5.3 does not constrain the sort direction to a valid asc or desc value.

Fix: 8.5.3+
Fix from $1,600 2020-06-22
Concrete Cms MEDIUM 6.1
CVE-2011-3183

A Cross-Site Scripting (XSS) vulnerability exists in the rcID parameter in Concrete CMS 5.4.1.1 and earlier.

Fix: after 5.4.1.1
Fix from $1,600 2020-01-14
Concrete Cms HIGH 7.2
CVE-2018-13790

A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network an…

No fix yet
Fix from $1,950 2018-07-09
Concrete Cms MEDIUM 5.3
CVE-2017-18195EPSS 11%

An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. An unauthenticated user can enumerate comments from all blog …

Fix: 8.3.0+
Fix from $1,600 2018-02-26
Concrete Cms HIGH 8.8
CVE-2015-4724

SQL injection vulnerability in Concrete5 5.7.3.1.

No fix yet
Fix from $1,950 2017-09-07
Concrete Cms MEDIUM 6.1
CVE-2015-4721

Multiple cross-site scripting (XSS) vulnerabilities in Concrete5 5.7.3.1.

No fix yet
Fix from $1,600 2017-09-07
Concrete Cms MEDIUM 6.5
CVE-2017-8082

concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking…

No fix yet
Fix from $1,600 2017-04-24
Concrete Cms MEDIUM 6.1
CVE-2017-7725

concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "canonical" URL on installation …

No fix yet
Fix from $1,600 2017-04-13