Vulnerability index

Browse CVEs

107 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-8204 Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend Dialog which can allow cross-calendar data disclosu… Concrete Cms 9.5.1+ Fix from $1,6002026-05-21 MEDIUM 5.3 CVE-2026-8205 Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calendar Block since action_get_events does not check canView on the calend… Concrete Cms after 9.5.0 Fix from $1,6002026-05-21 HIGH 7.2 CVE-2026-8134 Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page ty… Concrete Cms after 9.5.0 Fix from $1,9502026-05-21 HIGH 7.2 CVE-2026-8135 Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the ExpressEntryList block controll… Concrete Cms after 9.5.0 Fix from $1,9502026-05-21 MEDIUM 5.3 CVE-2026-6826 Concrete CMS 9.5.0 and below  is vulnerable to unauthenticated file usage disclosure via missing permission check in the usage controller.  Any unaut… Concrete Cms 9.5.1+ Fix from $1,6002026-05-21 MEDIUM 6.5 CVE-2026-30662 ConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. The 'download' method in 'concrete/controllers/bac… Concrete Cms No fix yet Fix from $1,6002026-03-24 MEDIUM 6.8 CVE-2026-2994 Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configuration via group_id parameter… Concrete Cms 9.4.8+ Fix from $1,6002026-03-04 HIGH 7.2 CVE-2026-3452 Concrete CMS below version 9.4.8 is vulnerable to Remote Code Execution by stored PHP object injection into the Express Entry List block via the colu… Concrete Cms 9.4.8+ Fix from $1,9502026-03-04 MEDIUM 6.5 CVE-2025-3153 Concrete CMS version 9 below 9.4.0RC2 and versions below 8.5.20 are vulnerable to CSRF and XSS in the Concrete CMS Address attribute because addresse… Concrete Cms 8.5.20 / 9.4.0+ Fix from $1,6002025-04-03 MEDIUM 5.4 CVE-2024-7398 Concrete CMS versions 9 through 9.3.3 and versions below 8.5.19 are vulnerable to stored XSS in the calendar event addition feature because the calen… Concrete Cms 8.5.19 / 9.3.3+ Fix from $1,6002024-09-25 CRITICAL 9.8 CVE-2023-48648 Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creatio… Concrete Cms 8.5.13 / 9.2.2+ Fix from $2,3002023-11-17 MEDIUM 5.4 CVE-2023-48649 Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows stored XSS on the Admin page via an uploaded file name. Concrete Cms 8.5.13 / 9.2.2+ Fix from $1,6002023-11-17 MEDIUM 5.4 CVE-2023-44763 Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cross-Site Scripting (XSS). NOTE:… Concrete Cms No fix yet Fix from $1,6002023-10-10 MEDIUM 5.4 CVE-2023-44761 Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS versions affected to 8.5.13 and below, and 9.0.0 through 9.2.1 allow a local atta… Concrete Cms No fix yet Fix from $1,6002023-10-06 MEDIUM 5.4 CVE-2023-44762 A Cross Site Scripting (XSS) vulnerability in Concrete CMS from versions 9.2.0 to 9.2.2 allows an attacker to execute arbitrary code via a crafted sc… Concrete Cms No fix yet Fix from $1,6002023-10-06 MEDIUM 5.4 CVE-2023-44764 A Cross Site Scripting (XSS) vulnerability in Concrete CMS before 9.2.3 exists via the Name parameter during installation (aka Site of Installation o… Concrete Cms No fix yet Fix from $1,6002023-10-06 MEDIUM 5.4 CVE-2023-44765 A Cross Site Scripting (XSS) vulnerability in Concrete CMS versions 8.5.12 and below, and 9.0 through 9.2.1 allows an attacker to execute arbitrary c… Concrete Cms No fix yet Fix from $1,6002023-10-06 MEDIUM 6.1 CVE-2023-28475 Concrete CMS (previously concrete5) versions 8.5.12 and below, and versions 9.0 through 9.1.3 is vulnerable to Reflected XSS on the Reply form becaus… Concrete Cms 9.2.0+ Fix from $1,6002023-04-28 MEDIUM 5.4 CVE-2023-28471 Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS via a container name. Concrete Cms 9.2.0+ Fix from $1,6002023-04-28 MEDIUM 5.4 CVE-2023-28474 Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Saved Presets on search. Concrete Cms 9.2.0+ Fix from $1,6002023-04-28 MEDIUM 5.4 CVE-2023-28476 Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Tags on uploaded files. Concrete Cms 9.2.0+ Fix from $1,6002023-04-28 MEDIUM 5.4 CVE-2023-28477 Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to stored XSS on API Integrations via the name par… Concrete Cms 9.2.0+ Fix from $1,6002023-04-28 MEDIUM 5.4 CVE-2023-28819 Concrete CMS (previously concrete5) versions 8.5.12 and below, 9.0.0 through 9.0.2 is vulnerable to Stored XSS in uploaded file and folder names. Concrete Cms 9.1.0+ Fix from $1,6002023-04-28 MEDIUM 5.4 CVE-2023-28820 Concrete CMS (previously concrete5) before 9.1 is vulnerable to stored XSS in RSS Displayer via the href attribute because the link element input was… Concrete Cms 9.1.0+ Fix from $1,6002023-04-28 MEDIUM 5.3 CVE-2023-28472 Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 does not have Secure and HTTP only attributes set for ccmPoll co… Concrete Cms 9.2.0+ Fix from $1,6002023-04-28 MEDIUM 5.3 CVE-2023-28821 Concrete CMS (previously concrete5) before 9.1 did not have a rate limit for password resets. Concrete Cms 9.1.0+ Fix from $1,6002023-04-28 MEDIUM 6.1 CVE-2022-43556 Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XSS in the text input field since the result dashboard pa… Concrete Cms 8.5.10+ Fix from $1,6002022-12-05 MEDIUM 6.3 CVE-2022-43690 Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 did not use strict comparison for the legacy_salt so that limited authenti… Concrete Cms 8.5.10+ Fix from $1,6002022-11-14 MEDIUM 5.3 CVE-2022-43689 Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XXE based DNS requests leading to IP disclosure. Concrete Cms 8.5.10+ Fix from $1,6002022-11-14 MEDIUM 5.3 CVE-2022-43691 Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 inadvertently disclose server-side sensitive information (secrets in envir… Concrete Cms 8.5.10+ Fix from $1,6002022-11-14