CVE-2023-44764
- EPSS 0.5%
- Veröffentlicht 06.10.2023 13:15:12
- Zuletzt bearbeitet 21.11.2024 08:26:01
A Cross Site Scripting (XSS) vulnerability in Concrete CMS before 9.2.3 exists via the Name parameter during installation (aka Site of Installation or Settings).
CVE-2023-44765
- EPSS 0.56%
- Veröffentlicht 06.10.2023 13:15:12
- Zuletzt bearbeitet 21.11.2024 08:26:01
A Cross Site Scripting (XSS) vulnerability in Concrete CMS versions 8.5.12 and below, and 9.0 through 9.2.1 allows an attacker to execute arbitrary code via a crafted script to Plural Handle of the Data Objects from System & Settings.
CVE-2023-44766
- EPSS 0.56%
- Veröffentlicht 06.10.2023 13:15:12
- Zuletzt bearbeitet 21.11.2024 08:26:01
A Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 allows an attacker to execute arbitrary code via a crafted script to the SEO - Extra from Page Settings. NOTE: the vendor disputes this because this SEO-related header change can only...
CVE-2023-28471
- EPSS 0.54%
- Veröffentlicht 28.04.2023 14:15:10
- Zuletzt bearbeitet 31.01.2025 17:15:10
Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS via a container name.
CVE-2023-28472
- EPSS 0.59%
- Veröffentlicht 28.04.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 07:55:09
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 does not have Secure and HTTP only attributes set for ccmPoll cookies.
CVE-2023-28473
- EPSS 0.76%
- Veröffentlicht 28.04.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 07:55:10
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to possible Auth bypass in the jobs section.
CVE-2023-28474
- EPSS 0.63%
- Veröffentlicht 28.04.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 07:55:10
Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Saved Presets on search.
CVE-2023-28475
- EPSS 0.64%
- Veröffentlicht 28.04.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 07:55:10
Concrete CMS (previously concrete5) versions 8.5.12 and below, and versions 9.0 through 9.1.3 is vulnerable to Reflected XSS on the Reply form because msgID was not sanitized.
CVE-2023-28476
- EPSS 0.54%
- Veröffentlicht 28.04.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 07:55:10
Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Tags on uploaded files.
CVE-2023-28477
- EPSS 0.58%
- Veröffentlicht 28.04.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 07:55:10
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to stored XSS on API Integrations via the name parameter.