← All credits
tenzai
15 vulnerability records and advisories credit this contributor.
CVE-2026-81897
Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via Express form Text control save_control
CVE-2026-81896
Concrete CMS below version 9.5.3 is vulnerable to Stored XSS in Concrete CMS Form Submissions Report via Unescaped Question Label
CVE-2026-81894
Concrete CMS 9.5.2 and below is vulnerable to Stored DOM-based Cross-site Scripting (XSS) in the Gallery block image Caption field
CVE-2026-81925
Concrete CMS below 9.5.3 is vulnerable to Reflected Cross-Site Scripting (XSS) via Conversation Custom Date Format
CVE-2026-81926
Concrete CMS 9.4.0 through 9.5.2 is vulnerable to Cross-site scripting in the location panel duplicate-path confirmation dialog
CVE-2026-81898
Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via country-less Address attribute in Express association views
CVE-2026-81901
Concrete CMS 9.2.0 to 9.5.2 is vulnerable to stored XSS due to missing authorization in the `PUT /pages/{cID}` endpoint
CVE-2026-81902
Concrete CMS 9.0.0 to 9.5.2 is vulnerable to CSRF on Orphan Block Cleanup
CVE-2026-81919
Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Block Arrangement Endpoint
CVE-2026-81916
Incorrect Authorization in the Concrete CMS Express Entries Dashboard below version 9.5.3 Allows Entry Creation in an Unauthorized Object