CVE-2024-8291
- EPSS 0.34%
- Veröffentlicht 25.09.2024 01:15:46
- Zuletzt bearbeitet 17.01.2025 22:15:29
Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in Image Editor Background Color. A rogue admin could add malicious code to the Thumbnails/Add-Type. The Concrete CMS Security Team gave this a CVSS v4 score of 5.1 w...
CVE-2024-7398
- EPSS 0.19%
- Veröffentlicht 25.09.2024 01:15:45
- Zuletzt bearbeitet 21.01.2025 00:15:25
Concrete CMS versions 9 through 9.3.3 and versions below 8.5.19 are vulnerable to stored XSS in the calendar event addition feature because the calendar event name was not sanitized on output. Users or groups with permission to create event calendars...
CVE-2024-8660
- EPSS 0.31%
- Veröffentlicht 17.09.2024 19:15:28
- Zuletzt bearbeitet 23.09.2024 23:00:00
Concrete CMS versions 9.0.0 through 9.3.3 are affected by a stored XSS vulnerability in the "Top Navigator Bar" block. Since the "Top Navigator Bar" output was not sufficiently sanitized, a rogue administrator could add a malicious payload that could...
CVE-2024-8661
- EPSS 0.54%
- Veröffentlicht 16.09.2024 18:15:54
- Zuletzt bearbeitet 16.12.2024 19:08:45
Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" block. A rogue administrator could add a malicious payload by executing it in the browsers of targeted users. The Concrete CMS Security Tea...
CVE-2024-7512
- EPSS 0.96%
- Veröffentlicht 12.08.2024 13:38:43
- Zuletzt bearbeitet 17.01.2025 21:15:10
Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in Board instances. A rogue administrator could inject malicious code. The Concrete CMS security team gave this vulnerability a CVSS 4.0 Score of 4.6 with vector: CV...
CVE-2024-4350
- EPSS 1.03%
- Veröffentlicht 12.08.2024 13:38:36
- Zuletzt bearbeitet 25.09.2025 19:15:41
Concrete CMS versions 9.0.0 to 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in RSS Displayer when user input is stored and later embedded into responses. A rogue administrator could inject malicious code into fields due to insufficient input v...
CVE-2024-7394
- EPSS 3.92%
- Veröffentlicht 08.08.2024 17:15:20
- Zuletzt bearbeitet 25.09.2025 19:15:42
Concrete CMS versions 9 through 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in getAttributeSetName(). A rogue administrator could inject malicious code. The Concrete CMS team gave this a CVSS v4.0 rank of 4.6 with vector https://www.first...
CVE-2024-4353
- EPSS 0.33%
- Veröffentlicht 01.08.2024 19:15:52
- Zuletzt bearbeitet 17.01.2025 22:15:28
Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in the generate dashboard board instance functionality. The Name input field does not check the input sufficiently letting a rogue administrator have the capability ...
CVE-2024-3181
- EPSS 0.1%
- Veröffentlicht 03.04.2024 20:15:07
- Zuletzt bearbeitet 16.12.2024 19:07:04
Concrete CMS version 9 prior to 9.2.8 and previous versions prior to 8.5.16 are vulnerable to Stored XSS in the Search Field. Prior to the fix, stored XSS could be executed by an administrator changing a filter to which a rogue administrator had prev...
CVE-2024-3178
- EPSS 0.1%
- Veröffentlicht 03.04.2024 19:15:44
- Zuletzt bearbeitet 16.12.2024 19:02:56
Concrete CMS versions 9 below 9.2.8 and versions below 8.5.16 are vulnerable to Cross-site Scripting (XSS) in the Advanced File Search Filter. Prior to the fix, a rogue administrator could add malicious code in the file manager because of insufficien...