| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-3179 | Concrete CMS version 9 before 9.2.8 and previous versions before 8.5.16 are vulnerable to Stored XSS in the Custom Class page | Concrete CMS | Concrete CMS | Low | 3.1 | 2024-04-03 18:50:46 | Deep Dive |
| CVE-2024-3178 | Concrete CMS versions 9 below 9.2.8 and versions below 8.5.16 are vulnerable to Cross-site Scripting (XSS) in the Advanced File Search Filter | Concrete CMS | Concrete CMS | Low | 3.1 | 2024-04-03 18:31:42 | Deep Dive |
| CVE-2024-2753 | Concrete CMS version 9 below 9.2.8 and below 8.5.16 is vulnerable to stored XSS on the calendar color settings screen | Concrete CMS | Concrete CMS | Low | 2.0 | 2024-04-03 18:13:41 | Deep Dive |
| CVE-2024-2179 | Concrete CMS version 9 before 9.2.7 is vulnerable to Stored XSS via the Name field of a Group type | Concrete CMS | Concrete CMS | Low | 2.2 | 2024-03-05 21:08:23 | Deep Dive |
| CVE-2024-1245 | Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributes | Concrete CMS | Concrete CMS | Low | 2.4 | 2024-02-09 19:43:58 | Deep Dive |
| CVE-2024-1246 | Concrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import Feature | Concrete CMS | Concrete CMS | Low | 2.0 | 2024-02-09 19:33:26 | Deep Dive |
| CVE-2024-1247 | Concrete CMS version 9 before 9.2.5 vulnerable to stored XSS via the Role Name field | Concrete CMS | Concrete CMS | Low | 2.0 | 2024-02-09 18:58:25 | Deep Dive |
| CVE-2011-3183 | Concrete CMS 跨站脚本漏洞 | Concrete CMS | Concrete CMS | 中危 | - | 2020-01-14 20:08:24 | Deep Dive |