VendorsConcrete CMSconcrete_cms8.4.3
Vulnerabilities

Concrete CMS Concrete CMS 8.4.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2018-19146
Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTML data with a SCRIPT element.
Published 2019-06-17 · Modified
4.8EPSS 0.010