orisec
2 credited records · 2 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
7Monitor | CVE-2026-81927No exploit | Concrete CMS before 9.5.3 is vulnerable to Stored XSS via SVG upload in "Reject" sanitization modeconcretecms · concrete cms · CWE-79 | Low1.8 | — | 0.2% | Sep 15, 2026 |
19Monitor | CVE-2026-81918No exploit | Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display blockconcretecms · concrete cms · CWE-79 | Medium4.8 | — | 0.3% | Sep 11, 2026 |
- CVE-2026-819277Monitor
Concrete CMS before 9.5.3 is vulnerable to Stored XSS via SVG upload in "Reject" sanitization mode
LowCVSS 1.8No exploitEPSS 0%concretecms · concrete cmsSep 15, 2026
- CVE-2026-8191819Monitor
Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block
MediumCVSS 4.8No exploitEPSS 0%concretecms · concrete cmsSep 11, 2026