Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
234 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.65% | — | Concretecms Concrete CMS | 27/9/2021 | 17/6/2026 | An issue was discovered in Concrete CMS through 8.5.5. There is XSS via Markdown Comments. | |
| Modificada | Alta (7.5) | 1.4% | — | Concretecms Concrete CMS | 27/9/2021 | 17/6/2026 | An issue was discovered in Concrete CMS through 8.5.5. There is an SVG sanitizer bypass. | |
| Modificada | Alta (7.5) | 1.5% | — | Concretecms Concrete CMS | 27/9/2021 | 17/6/2026 | An issue was discovered in Concrete CMS through 8.5.5. Path Traversal can lead to Arbitrary File Reading and SSRF. | |
| Modificada | Crítica (9.8) | 1.6% | — | Concretecms Concrete CMS | 27/9/2021 | 17/6/2026 | An issue was discovered in Concrete CMS through 8.5.5. Path Traversal leading to RCE via external form by adding a regular expression. | |
| Modificada | Alta (8.8) | 2.5% | — | Concretecms Concrete CMS | 27/9/2021 | 17/6/2026 | An issue was discovered in Concrete CMS through 8.5.5. Authenticated path traversal leads to to remote code execution via uploaded PHP code, related to the bFilename parameter. | |
| Modificada | Crítica (9.1) | 1.3% | — | Concretecms Concrete CMS | 24/9/2021 | 17/6/2026 | An issue was discovered in Concrete CMS through 8.5.5. Arbitrary File deletion can occur via PHAR deserialization in is_dir (PHP Object Injection associated with the __wakeup magic method). | |
| Modificada | Media (5.4) | 0.52% | — | Concretecms Concrete CMS | 24/9/2021 | 17/6/2026 | An issue was discovered in Concrete CMS through 8.5.5. Stored XSS can occur in Conversations when the Active Conversation Editor is set to Rich Text. | |
| Modificada | Alta (7.2) | 2.1% | — | Concretecms Concrete CMS | 24/9/2021 | 17/6/2026 | An issue was discovered in Concrete CMS through 8.5.5. Fetching the update json scheme over HTTP leads to remote code execution. | |
| Modificada | Media (5.4) | 0.36% | — | Concretecms Concrete CMS | 23/9/2021 | 17/6/2026 | A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security Research Team" | |
| Modificada | Media (6.5) | 0.44% | — | Concretecms Concrete CMS | 23/9/2021 | 17/6/2026 | Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for discovery: "Solar Security Research Team" | |
| Modificada | Media (5.4) | 0.36% | — | Concretecms Concrete CMS | 23/9/2021 | 17/6/2026 | A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security CMS Research Team" | |
| Modificada | Alta (7.2) | 3.7% | — | Concretecms Concrete CMS | 30/7/2021 | 17/6/2026 | Concrete5 through 8.5.5 deserializes Untrusted Data. The vulnerable code is located within the controllers/single_page/dashboard/system/environment/logging.php Logging::update_logging() method. User input passed through the logFile request parameter is not properly sanitized before being used in a call to the… | |
| Modificada | Media (5.4) | 0.86% | — | Concretecms Concrete CMS | 18/3/2021 | 17/6/2026 | Concrete CMS (formerly concrete5) before 8.5.5 allows remote authenticated users to conduct XSS attacks via a crafted survey block. This requires at least Editor privileges. | |
| Modificada | Media (4.8) | 3.0% | 💥 Exploit | Concretecms Concrete CMS | 8/1/2021 | 17/6/2026 | The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.php/dashboard/express/entries/view/ URI. | |
| Modificada | Alta (7.2) | 2.0% | — | Concretecms Concrete CMS | 4/9/2020 | 17/6/2026 | Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File Manager. It is possible to modify site configuration to upload the PHP file and execute arbitrary commands. | |
| Modificada | Alta (7.2) | 2.9% | — | Concretecms Concrete CMS | 28/7/2020 | 17/6/2026 | Concrete5 before 8.5.3 allows Unrestricted Upload of File with Dangerous Type such as a .phar file. | |
| Modificada | Media (5.3) | 0.94% | — | Concretecms Concrete CMS | 22/6/2020 | 17/6/2026 | Concrete5 before 8.5.3 does not constrain the sort direction to a valid asc or desc value. | |
| Modificada | Media (6.1) | 0.69% | — | Concretecms Concrete CMS | 14/1/2020 | 16/6/2026 | A Cross-Site Scripting (XSS) vulnerability exists in the rcID parameter in Concrete CMS 5.4.1.1 and earlier. | |
| Modificada | Media (4.8) | 0.99% | — | Concretecms Concrete CMS | 17/6/2019 | 17/6/2026 | Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTML data with a SCRIPT element. | |
| Modificada | Alta (7.2) | 1.0% | — | Concretecms Concrete CMS | 9/7/2018 | 17/6/2026 | A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network and mapping of the internal network, because of URL functionality on the File Manager page. | |
| Modificada | Media (5.3) | 11% | 💥 Exploit | Concretecms Concrete CMS | 26/2/2018 | 17/6/2026 | An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. An unauthenticated user can enumerate comments from all blog posts by POSTing requests to /index.php/tools/required/conversations/view_ajax with incremental 'cnvID' integers. | |
| Modificada | Alta (8.8) | 0.84% | — | Concretecms Concrete CMS | 7/9/2017 | 17/6/2026 | SQL injection vulnerability in Concrete5 5.7.3.1. | |
| Modificada | Media (6.1) | 0.74% | — | Concretecms Concrete CMS | 7/9/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Concrete5 5.7.3.1. | |
| Modificada | Media (6.5) | 1.2% | — | Concretecms Concrete CMS | 24/4/2017 | 17/6/2026 | concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking an admin into viewing a malicious page involving the /tools/required/files/importers/imageeditor?fID=1&imgData= URI. This results in a site-wide denial of service making… | |
| Modificada | Media (6.1) | 2.8% | 💥 Exploit | Concretecms Concrete CMS | 13/4/2017 | 17/6/2026 | concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "canonical" URL on installation of concrete5 using the "Advanced Options" settings. Remote attackers can make a GET request with any domain name in the Host header; this is stored and allows for… |