Vulnerability index

Browse CVEs

107 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2021-40099 An issue was discovered in Concrete CMS through 8.5.5. Fetching the update json scheme over HTTP leads to remote code execution. Concrete Cms after 8.5.5 Fix from $1,9502021-09-24 MEDIUM 5.4 CVE-2021-40100 An issue was discovered in Concrete CMS through 8.5.5. Stored XSS can occur in Conversations when the Active Conversation Editor is set to Rich Text. Concrete Cms after 8.5.5 Fix from $1,6002021-09-24 MEDIUM 5.4 CVE-2021-22953 A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of disk space.Cr… Concrete Cms after 8.5.5 Fix from $1,6002021-09-23 MEDIUM 6.5 CVE-2021-22950 Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for discovery:… Concrete Cms 8.5.6+ Fix from $1,6002021-09-23 MEDIUM 5.4 CVE-2021-22949 A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space… Concrete Cms after 8.5.5 Fix from $1,6002021-09-23 HIGH 7.2 CVE-2021-36766 Concrete5 through 8.5.5 deserializes Untrusted Data. The vulnerable code is located within the controllers/single_page/dashboard/system/environment/l… Concrete Cms 8.5.6+ Fix from $1,9502021-07-30 MEDIUM 5.4 CVE-2021-28145 Concrete CMS (formerly concrete5) before 8.5.5 allows remote authenticated users to conduct XSS attacks via a crafted survey block. This requires at … Concrete Cms 8.5.5+ Fix from $1,6002021-03-18 HIGH 7.2 CVE-2020-24986 Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File Manager. It is possible to mo… Concrete Cms after 8.5.2 Fix from $1,9502020-09-04 HIGH 7.2 CVE-2020-11476 Concrete5 before 8.5.3 allows Unrestricted Upload of File with Dangerous Type such as a .phar file. Concrete Cms 8.5.3+ Fix from $1,9502020-07-28 MEDIUM 5.3 CVE-2020-14961 Concrete5 before 8.5.3 does not constrain the sort direction to a valid asc or desc value. Concrete Cms 8.5.3+ Fix from $1,6002020-06-22 MEDIUM 6.1 CVE-2011-3183 A Cross-Site Scripting (XSS) vulnerability exists in the rcID parameter in Concrete CMS 5.4.1.1 and earlier. Concrete Cms after 5.4.1.1 Fix from $1,6002020-01-14 HIGH 7.2 CVE-2018-13790 A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network an… Concrete Cms No fix yet Fix from $1,9502018-07-09 MEDIUM 5.3 CVE-2017-18195EPSS 11% An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. An unauthenticated user can enumerate comments from all blog … Concrete Cms 8.3.0+ Fix from $1,6002018-02-26 HIGH 8.8 CVE-2015-4724 SQL injection vulnerability in Concrete5 5.7.3.1. Concrete Cms No fix yet Fix from $1,9502017-09-07 MEDIUM 6.1 CVE-2015-4721 Multiple cross-site scripting (XSS) vulnerabilities in Concrete5 5.7.3.1. Concrete Cms No fix yet Fix from $1,6002017-09-07 MEDIUM 6.5 CVE-2017-8082 concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking… Concrete Cms No fix yet Fix from $1,6002017-04-24 MEDIUM 6.1 CVE-2017-7725 concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "canonical" URL on installation … Concrete Cms No fix yet Fix from $1,6002017-04-13