tenzai
15 kredili kayıt · son 12 ayda 15 · 0 tanesi CISA KEV’de
Adlar CNA kayıtlarındaki serbest metindir; aynı kişi farklı yazımlarla ayrı görünebilir. Düzeltme için bize yazın.
Kredili kayıtlar
Araştırmacılar| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
8İzleyin | CVE-2026-81926İstismar yok | Concrete CMS 9.4.0 through 9.5.2 is vulnerable to Cross-site scripting in the location panel duplicate-path confirmation dialogconcretecms · concrete cms · CWE-79 | Düşük2,0 | — | %0,3 | 15 Eyl 2026 |
8İzleyin | CVE-2026-81925İstismar yok | Concrete CMS below 9.5.3 is vulnerable to Reflected Cross-Site Scripting (XSS) via Conversation Custom Date Formatconcretecms · concrete cms · CWE-79 | Düşük2,1 | — | %0,3 | 15 Eyl 2026 |
9İzleyin | CVE-2026-81919İstismar yok | Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Block Arrangement Endpointconcretecms · concrete cms · CWE-352 | Düşük2,3 | — | %0,1 | 15 Eyl 2026 |
30İzleyin | CVE-2026-81898İstismar yok | Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via country-less Address attribute in Express association viewsconcrete cms · concrete cms · CWE-79 | Yüksek7,5 | — | %0,4 | 15 Eyl 2026 |
30İzleyin | CVE-2026-81897İstismar yok | Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via Express form Text control save_controlconcretecms · concrete cms · CWE-79 | Yüksek7,7 | — | %0,2 | 15 Eyl 2026 |
33İzleyin | CVE-2026-81896İstismar yok | Concrete CMS below version 9.5.3 is vulnerable to Stored XSS in Concrete CMS Form Submissions Report via Unescaped Question Labelconcretecms · concrete cms · CWE-79 | Yüksek8,4 | — | %0,2 | 15 Eyl 2026 |
34İzleyin | CVE-2026-81894İstismar yok | Concrete CMS 9.5.2 and below is vulnerable to Stored DOM-based Cross-site Scripting (XSS) in the Gallery block image Caption fieldconcretecms · concrete cms · CWE-89 | Yüksek8,5 | — | %0,2 | 15 Eyl 2026 |
28İzleyin | CVE-2026-81902İstismar yok | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to CSRF on Orphan Block Cleanupconcretecms · concrete cms · CWE-352 | Yüksek7,1 | — | %0,2 | 14 Eyl 2026 |
28İzleyin | CVE-2026-81901İstismar yok | Concrete CMS 9.2.0 to 9.5.2 is vulnerable to stored XSS due to missing authorization in the `PUT /pages/{cID}` endpointconcretecms · concrete cms · CWE-862 | Yüksek7,2 | — | %0,4 | 14 Eyl 2026 |
20İzleyin | CVE-2026-81916İstismar yok | Incorrect Authorization in the Concrete CMS Express Entries Dashboard below version 9.5.3 Allows Entry Creation in an Unauthorized Objectconcretecms · concrete cms · CWE-639 | Orta5,1 | — | %0,3 | 11 Eyl 2026 |
23İzleyin | CVE-2026-81910İstismar yok | Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Valuesconcretecms · concrete cms · CWE-1336 | Orta5,9 | — | %0,4 | 11 Eyl 2026 |
23İzleyin | CVE-2026-81909İstismar yok | Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block alias route, allowing an authenticated editor to disclose and force-deconcrete cms · concrete cms · CWE-862 | Orta5,9 | — | %0,4 | 11 Eyl 2026 |
25İzleyin | CVE-2026-81906İstismar yok | [UNREVIEWED] OAuth Callback Login Bypasses Deactivated-Account Checksconcrete cms · concrete cms · CWE-288 | Orta6,3 | — | %0,6 | 10 Eyl 2026 |
25İzleyin | CVE-2026-81905İstismar yok | Concrete CMS below 9.5.3 does not enforce validation-hash type on redemption, allowing a hash issued for one purpose to be redeemed for another.concrete cms · concrete cms · CWE-640 | Orta6,3 | — | %0,4 | 10 Eyl 2026 |
25İzleyin | CVE-2026-81904İstismar yok | Concrete CMS before 9.5.3 is vulnerable to Missing Authorization in Stack/Container Sub-Block Asset Registrationconcrete cms · concrete cms · CWE-862 | Orta6,3 | — | %0,5 | 8 Eyl 2026 |
- CVE-2026-819268İzleyin
Concrete CMS 9.4.0 through 9.5.2 is vulnerable to Cross-site scripting in the location panel duplicate-path confirmation dialog
DüşükCVSS 2,0İstismar yokEPSS %0concretecms · concrete cms15 Eyl 2026
- CVE-2026-819258İzleyin
Concrete CMS below 9.5.3 is vulnerable to Reflected Cross-Site Scripting (XSS) via Conversation Custom Date Format
DüşükCVSS 2,1İstismar yokEPSS %0concretecms · concrete cms15 Eyl 2026
- CVE-2026-819199İzleyin
Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Block Arrangement Endpoint
DüşükCVSS 2,3İstismar yokEPSS %0concretecms · concrete cms15 Eyl 2026
- CVE-2026-8189830İzleyin
Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via country-less Address attribute in Express association views
YüksekCVSS 7,5İstismar yokEPSS %0concrete cms · concrete cms15 Eyl 2026
- CVE-2026-8189730İzleyin
Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via Express form Text control save_control
YüksekCVSS 7,7İstismar yokEPSS %0concretecms · concrete cms15 Eyl 2026
- CVE-2026-8189633İzleyin
Concrete CMS below version 9.5.3 is vulnerable to Stored XSS in Concrete CMS Form Submissions Report via Unescaped Question Label
YüksekCVSS 8,4İstismar yokEPSS %0concretecms · concrete cms15 Eyl 2026
- CVE-2026-8189434İzleyin
Concrete CMS 9.5.2 and below is vulnerable to Stored DOM-based Cross-site Scripting (XSS) in the Gallery block image Caption field
YüksekCVSS 8,5İstismar yokEPSS %0concretecms · concrete cms15 Eyl 2026
- CVE-2026-8190228İzleyin
Concrete CMS 9.0.0 to 9.5.2 is vulnerable to CSRF on Orphan Block Cleanup
YüksekCVSS 7,1İstismar yokEPSS %0concretecms · concrete cms14 Eyl 2026
- CVE-2026-8190128İzleyin
Concrete CMS 9.2.0 to 9.5.2 is vulnerable to stored XSS due to missing authorization in the `PUT /pages/{cID}` endpoint
YüksekCVSS 7,2İstismar yokEPSS %0concretecms · concrete cms14 Eyl 2026
- CVE-2026-8191620İzleyin
Incorrect Authorization in the Concrete CMS Express Entries Dashboard below version 9.5.3 Allows Entry Creation in an Unauthorized Object
OrtaCVSS 5,1İstismar yokEPSS %0concretecms · concrete cms11 Eyl 2026
- CVE-2026-8191023İzleyin
Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values
OrtaCVSS 5,9İstismar yokEPSS %0concretecms · concrete cms11 Eyl 2026
- CVE-2026-8190923İzleyin
Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block alias route, allowing an authenticated editor to disclose and force-de
OrtaCVSS 5,9İstismar yokEPSS %0concrete cms · concrete cms11 Eyl 2026
- CVE-2026-8190625İzleyin
[UNREVIEWED] OAuth Callback Login Bypasses Deactivated-Account Checks
OrtaCVSS 6,3İstismar yokEPSS %1concrete cms · concrete cms10 Eyl 2026
- CVE-2026-8190525İzleyin
Concrete CMS below 9.5.3 does not enforce validation-hash type on redemption, allowing a hash issued for one purpose to be redeemed for another.
OrtaCVSS 6,3İstismar yokEPSS %0concrete cms · concrete cms10 Eyl 2026
- CVE-2026-8190425İzleyin
Concrete CMS before 9.5.3 is vulnerable to Missing Authorization in Stack/Container Sub-Block Asset Registration
OrtaCVSS 6,3İstismar yokEPSS %0concrete cms · concrete cms8 Eyl 2026