Conceptintermedia's vulnerability footprint is concentrated in its S@M CMS web content management product, with observed weaknesses centered on application-layer input handling including cross-site scripting and SQL injection. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Conceptintermedia over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-3816CRITICAL Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to a blind SQL Injection executed using the search bar.
Only a part of observed services is vulnerable, but since | Jun 28, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-3800MEDIUM Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in requested file names.
Only a part of observed services is vulnerable, b | Jun 28, 2024 | 6.1 | 19 | NO | NO |
CVE-2024-3801MEDIUM Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in one of GET header parameters.
Only a part of observed services is vulne | Jun 28, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Conceptintermedia.
Media articles that mention a CVE ID that affects a product developed by Conceptintermedia — matched by CVE ID, not by vendor name.