|
2161
|
4.3 |
MEDIUM
Network
|
concretecms
|
concrete_cms
|
Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail block via the exEntryID parameter. This IDOR leads to unauthorized access to all Express…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-7881
|
2026-05-23 04:19 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2162
|
5.3 |
MEDIUM
Network
|
concretecms
|
concrete_cms
|
In Concrete CMS 9.5.0 and below, the submit_password() method in concrete/controllers/single_page/download_file.php allows unauthorized file access since downloading
permission-restricted files bypa…
|
CWE-862
Missing Authorization
|
CVE-2026-7879
|
2026-05-23 04:18 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2163
|
6.5 |
MEDIUM
Network
|
-
|
-
|
TypeBot is a chatbot builder tool. In versions 3.15.2, the getLinkedTypebots API endpoint returns full bot definitions to any authenticated user who references a target bot ID in a Typebot Link block…
|
CWE-863
Incorrect Authorization
|
CVE-2026-39966
|
2026-05-23 04:18 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2164
|
4.8 |
MEDIUM
Network
|
concretecms
|
concrete_cms
|
Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inject arbitrary JavaScript that executes in the context of any authenticated user …
|
CWE-79
Cross-site Scripting
|
CVE-2026-8353
|
2026-05-23 04:17 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2165
|
7.7 |
HIGH
Network
|
-
|
-
|
TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an SSRF via Open Redirect Bypass as the HTTP Request block and Code block validate the initial request URL via validateHttpReqUrl(…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-39965
|
2026-05-23 04:17 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2166
|
7.6 |
HIGH
Network
|
-
|
-
|
TypeBot is a chatbot builder tool. In versions prior to 3.16.0, SSRF protection for Webhook / HTTP Request blocks validates only the URL string, blocked hostname literals, and literal IP formats. It …
|
CWE-20 CWE-918
Improper Input Validation Server-Side Request Forgery (SSRF)
|
CVE-2026-34207
|
2026-05-23 04:17 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2167
|
4.3 |
MEDIUM
Network
|
concretecms
|
concrete_cms
|
Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog. This can cause Cross-entity state tampering with view-only permission on one…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-8347
|
2026-05-23 04:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2168
|
6.5 |
MEDIUM
Network
|
concretecms
|
concrete_cms
|
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion(). The Concrete CMS security team gave this vulnerability a CVSS v.4…
|
CWE-352 CWE-1275
Origin Validation Error Sensitive Cookie with Improper SameSite Attribute
|
CVE-2026-8435
|
2026-05-23 04:15 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2169
|
6.7 |
MEDIUM
Local
|
dell
|
smartfabric_storage_software
|
Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker w…
|
CWE-77
Command Injection
|
CVE-2026-35070
|
2026-05-23 04:14 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2170
|
6.4 |
MEDIUM
Network
|
concretecms
|
concrete_cms
|
In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation enabling redirect-to-internal bypasses. The Concrete CM…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-7890
|
2026-05-23 04:12 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|