İçeriğe atla
Noroxi

tenzai

15 kredili kayıt · son 12 ayda 15 · 0 tanesi CISA KEV’de

Adlar CNA kayıtlarındaki serbest metindir; aynı kişi farklı yazımlarla ayrı görünebilir. Düzeltme için bize yazın.

Kredili kayıtlar

Araştırmacılar
  • Concrete CMS 9.4.0 through 9.5.2 is vulnerable to Cross-site scripting in the location panel duplicate-path confirmation dialog

    DüşükCVSS 2,0İstismar yokEPSS %0

    concretecms · concrete cms15 Eyl 2026

  • Concrete CMS below 9.5.3 is vulnerable to Reflected Cross-Site Scripting (XSS) via Conversation Custom Date Format

    DüşükCVSS 2,1İstismar yokEPSS %0

    concretecms · concrete cms15 Eyl 2026

  • Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Block Arrangement Endpoint

    DüşükCVSS 2,3İstismar yokEPSS %0

    concretecms · concrete cms15 Eyl 2026

  • CVE-2026-81898
    30İzleyin

    Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via country-less Address attribute in Express association views

    YüksekCVSS 7,5İstismar yokEPSS %0

    concrete cms · concrete cms15 Eyl 2026

  • CVE-2026-81897
    30İzleyin

    Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via Express form Text control save_control

    YüksekCVSS 7,7İstismar yokEPSS %0

    concretecms · concrete cms15 Eyl 2026

  • CVE-2026-81896
    33İzleyin

    Concrete CMS below version 9.5.3 is vulnerable to Stored XSS in Concrete CMS Form Submissions Report via Unescaped Question Label

    YüksekCVSS 8,4İstismar yokEPSS %0

    concretecms · concrete cms15 Eyl 2026

  • CVE-2026-81894
    34İzleyin

    Concrete CMS 9.5.2 and below is vulnerable to Stored DOM-based Cross-site Scripting (XSS) in the Gallery block image Caption field

    YüksekCVSS 8,5İstismar yokEPSS %0

    concretecms · concrete cms15 Eyl 2026

  • CVE-2026-81902
    28İzleyin

    Concrete CMS 9.0.0 to 9.5.2 is vulnerable to CSRF on Orphan Block Cleanup

    YüksekCVSS 7,1İstismar yokEPSS %0

    concretecms · concrete cms14 Eyl 2026

  • CVE-2026-81901
    28İzleyin

    Concrete CMS 9.2.0 to 9.5.2 is vulnerable to stored XSS due to missing authorization in the `PUT /pages/{cID}` endpoint

    YüksekCVSS 7,2İstismar yokEPSS %0

    concretecms · concrete cms14 Eyl 2026

  • CVE-2026-81916
    20İzleyin

    Incorrect Authorization in the Concrete CMS Express Entries Dashboard below version 9.5.3 Allows Entry Creation in an Unauthorized Object

    OrtaCVSS 5,1İstismar yokEPSS %0

    concretecms · concrete cms11 Eyl 2026

  • CVE-2026-81910
    23İzleyin

    Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values

    OrtaCVSS 5,9İstismar yokEPSS %0

    concretecms · concrete cms11 Eyl 2026

  • CVE-2026-81909
    23İzleyin

    Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block alias route, allowing an authenticated editor to disclose and force-de

    OrtaCVSS 5,9İstismar yokEPSS %0

    concrete cms · concrete cms11 Eyl 2026

  • CVE-2026-81906
    25İzleyin

    [UNREVIEWED] OAuth Callback Login Bypasses Deactivated-Account Checks

    OrtaCVSS 6,3İstismar yokEPSS %1

    concrete cms · concrete cms10 Eyl 2026

  • CVE-2026-81905
    25İzleyin

    Concrete CMS below 9.5.3 does not enforce validation-hash type on redemption, allowing a hash issued for one purpose to be redeemed for another.

    OrtaCVSS 6,3İstismar yokEPSS %0

    concrete cms · concrete cms10 Eyl 2026

  • CVE-2026-81904
    25İzleyin

    Concrete CMS before 9.5.3 is vulnerable to Missing Authorization in Stack/Container Sub-Block Asset Registration

    OrtaCVSS 6,3İstismar yokEPSS %0

    concrete cms · concrete cms8 Eyl 2026