Vulnerabilities > Concrete5 > Concrete5 > 5.6.3.3

DATE CVE VULNERABILITY TITLE RISK
2017-03-15 CVE-2017-6908 Cross-site Scripting vulnerability in Concrete5
An issue was discovered in concrete5 <= 5.6.3.4.
network
concrete5 CWE-79
4.3
2017-03-15 CVE-2017-6905 Cross-site Scripting vulnerability in Concrete5
An issue was discovered in concrete5 <= 5.6.3.4.
network
concrete5 CWE-79
4.3
2015-05-15 CVE-2015-3989 Cross-site Scripting vulnerability in Concrete5
Multiple cross-site scripting (XSS) vulnerabilities in concrete5 before 5.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to private messages or other unspecified vectors.
network
concrete5 CWE-79
4.3
2015-05-15 CVE-2015-2250 Cross-site Scripting vulnerability in Concrete5
Multiple cross-site scripting (XSS) vulnerabilities in concrete5 before 5.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) banned_word[] parameter to index.php/dashboard/system/conversations/bannedwords/success, (2) channel parameter to index.php/dashboard/reports/logs/view, (3) accessType parameter to index.php/tools/required/permissions/access_entity, (4) msCountry parameter to index.php/dashboard/system/multilingual/setup/load_icon, arHandle parameter to (5) design/submit or (6) design in index.php/ccm/system/dialogs/area/design/submit, (7) pageURL to index.php/dashboard/pages/single, (8) SEARCH_INDEX_AREA_METHOD parameter to index.php/dashboard/system/seo/searchindex/updated, (9) unit parameter to index.php/dashboard/system/optimization/jobs/job_scheduled, (10) register_notification_email parameter to index.php/dashboard/system/registration/open/1, or (11) PATH_INFO to index.php/dashboard/extend/connect/.
network
concrete5 CWE-79
4.3
2015-01-05 CVE-2014-9526 Cross-site Scripting vulnerability in multiple products
Multiple cross-site scripting (XSS) vulnerabilities in concrete5 5.7.2.1, 5.7.2, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gName parameter in single_pages/dashboard/users/groups/bulkupdate.php or (2) instance_id parameter in tools/dashboard/sitemap_drag_request.php.
4.3