Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.2
CVE-2021-40099
An issue was discovered in Concrete CMS through 8.5.5. Fetching the update json scheme over HTTP leads to remote code execution.
Concrete Cms
after 8.5.5
MEDIUM 5.4
CVE-2021-40100
An issue was discovered in Concrete CMS through 8.5.5. Stored XSS can occur in Conversations when the Active Conversation Editor is set to Rich Text.
Concrete Cms
after 8.5.5
MEDIUM 5.4
CVE-2021-22953
A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of disk space.Cr…
Concrete Cms
after 8.5.5
MEDIUM 6.5
CVE-2021-22950
Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for discovery:…
Concrete Cms
8.5.6+
MEDIUM 5.4
CVE-2021-22949
A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space…
Concrete Cms
after 8.5.5
HIGH 7.2
CVE-2021-36766
Concrete5 through 8.5.5 deserializes Untrusted Data. The vulnerable code is located within the controllers/single_page/dashboard/system/environment/l…
Concrete Cms
8.5.6+
MEDIUM 5.4
CVE-2021-28145
Concrete CMS (formerly concrete5) before 8.5.5 allows remote authenticated users to conduct XSS attacks via a crafted survey block. This requires at …
Concrete Cms
8.5.5+
HIGH 7.2
CVE-2020-24986
Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File Manager. It is possible to mo…
Concrete Cms
after 8.5.2
HIGH 7.2
CVE-2020-11476
Concrete5 before 8.5.3 allows Unrestricted Upload of File with Dangerous Type such as a .phar file.
Concrete Cms
8.5.3+
MEDIUM 5.3
CVE-2020-14961
Concrete5 before 8.5.3 does not constrain the sort direction to a valid asc or desc value.
Concrete Cms
8.5.3+
MEDIUM 6.1
CVE-2011-3183
A Cross-Site Scripting (XSS) vulnerability exists in the rcID parameter in Concrete CMS 5.4.1.1 and earlier.
Concrete Cms
after 5.4.1.1
HIGH 7.2
CVE-2018-13790
A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network an…
Concrete Cms
No fix yet
MEDIUM 5.3
CVE-2017-18195EPSS 11%
An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. An unauthenticated user can enumerate comments from all blog …
Concrete Cms
8.3.0+
HIGH 8.8
CVE-2015-4724
SQL injection vulnerability in Concrete5 5.7.3.1.
Concrete Cms
No fix yet
MEDIUM 6.1
CVE-2015-4721
Multiple cross-site scripting (XSS) vulnerabilities in Concrete5 5.7.3.1.
Concrete Cms
No fix yet
MEDIUM 6.5
CVE-2017-8082
concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking…
Concrete Cms
No fix yet
MEDIUM 6.1
CVE-2017-7725
concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "canonical" URL on installation …
Concrete Cms
No fix yet