Concrete5 is a modestly represented content-management and website-building platform whose vulnerability disclosures concentrate within a narrow product scope. The recurring weakness classes affecting the platform center on cross-site scripting and sensitive-information exposure, reflecting the web-application input-handling and data-protection demands of a CMS that processes user-generated content and manages site configurations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Concrete5 over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-6908MEDIUM An issue was discovered in concrete5 <= 5.6.3.4. The vulnerability exists due to insufficient filtration of user-supplied data (fID) passed to the "concrete5-legacy-master/web/conc | Mar 15, 2017 | 6.1 | 21 | NO | NO |
CVE-2017-6905MEDIUM An issue was discovered in concrete5 <= 5.6.3.4. The vulnerability exists due to insufficient filtration of user-supplied data (disable_choose) passed to the "concrete5-legacy-mast | Mar 15, 2017 | 6.1 | 20 | NO | NO |
CVE-2014-5107MEDIUM concrete5 before 5.6.3 allows remote attackers to obtain the installation path via a direct request to (1) system/basics/editor.php, (2) system/view.php, (3) system/environment/fil | Jul 28, 2014 | 5.0 | 20 | NO | NO |
CVE-2012-5181MEDIUM Cross-site scripting (XSS) vulnerability in concrete5 Japanese 5.5.1 through 5.5.2.1 and concrete5 English 5.5.0 through 5.6.0.2 allows remote attackers to inject arbitrary web scr | Dec 21, 2012 | 4.3 | 19 | NO | NO |
CVE-2014-5108MEDIUM Cross-site scripting (XSS) vulnerability in single_pages\download_file.php in concrete5 before 5.6.3 allows remote attackers to inject arbitrary web script or HTML via the HTTP Ref | Jul 28, 2014 | 4.3 | 18 | NO | NO |
CVE-2011-3721MEDIUM concrete 5.4.0.5, 5.4.1, and 5.4.1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error me | Sep 23, 2011 | 5.0 | 15 | NO | NO |
CVE-2015-3989MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in concrete5 before 5.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to private messages | May 15, 2015 | 4.3 | 14 | NO | NO |
CVE-2015-2250MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in concrete5 before 5.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) banned_word[] parameter to i | May 15, 2015 | 4.3 | 14 | NO | NO |
CVE-2014-9526MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in concrete5 5.7.2.1, 5.7.2, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gName paramet | Jan 5, 2015 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Concrete5.
Media articles that mention a CVE ID that affects a product developed by Concrete5 — matched by CVE ID, not by vendor name.