Concretecms

Concrete Cms

119 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.17%
  • Veröffentlicht 06.10.2023 13:15:12
  • Zuletzt bearbeitet 21.11.2024 08:26:01

A Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 allows an attacker to execute arbitrary code via a crafted script to the SEO - Extra from Page Settings. NOTE: the vendor disputes this because this SEO-related header change can only...

  • EPSS 1.23%
  • Veröffentlicht 28.04.2023 14:15:10
  • Zuletzt bearbeitet 31.01.2025 17:15:10

Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS via a container name.

  • EPSS 0.34%
  • Veröffentlicht 28.04.2023 14:15:10
  • Zuletzt bearbeitet 21.11.2024 07:55:09

Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 does not have Secure and HTTP only attributes set for ccmPoll cookies.

  • EPSS 0.16%
  • Veröffentlicht 28.04.2023 14:15:10
  • Zuletzt bearbeitet 21.11.2024 07:55:10

Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to possible Auth bypass in the jobs section.

  • EPSS 1.23%
  • Veröffentlicht 28.04.2023 14:15:10
  • Zuletzt bearbeitet 21.11.2024 07:55:10

Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Saved Presets on search.

  • EPSS 1.33%
  • Veröffentlicht 28.04.2023 14:15:10
  • Zuletzt bearbeitet 21.11.2024 07:55:10

Concrete CMS (previously concrete5) versions 8.5.12 and below, and versions 9.0 through 9.1.3 is vulnerable to Reflected XSS on the Reply form because msgID was not sanitized.

  • EPSS 1.6%
  • Veröffentlicht 28.04.2023 14:15:10
  • Zuletzt bearbeitet 21.11.2024 07:55:10

Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Tags on uploaded files.

  • EPSS 0.96%
  • Veröffentlicht 28.04.2023 14:15:10
  • Zuletzt bearbeitet 21.11.2024 07:55:10

Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to stored XSS on API Integrations via the name parameter.

  • EPSS 2.54%
  • Veröffentlicht 28.04.2023 14:15:10
  • Zuletzt bearbeitet 21.11.2024 07:56:04

Concrete CMS (previously concrete5) versions 8.5.12 and below, 9.0.0 through 9.0.2 is vulnerable to Stored XSS in uploaded file and folder names.

  • EPSS 0.69%
  • Veröffentlicht 28.04.2023 14:15:10
  • Zuletzt bearbeitet 31.01.2025 17:15:10

Concrete CMS (previously concrete5) before 9.1 is vulnerable to stored XSS in RSS Displayer via the href attribute because the link element input was not sanitized.