Skip to content
Noroxi

orisec

2 credited records · 2 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • Concrete CMS before 9.5.3 is vulnerable to Stored XSS via SVG upload in "Reject" sanitization mode

    LowCVSS 1.8No exploitEPSS 0%

    concretecms · concrete cmsSep 15, 2026

  • Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block

    MediumCVSS 4.8No exploitEPSS 0%

    concretecms · concrete cmsSep 11, 2026