Vulnerability Database

313,825

Total vulnerabilities in the database

CVE-2023-28820

Concrete CMS (previously concrete5) before 9.1 is vulnerable to stored XSS in RSS Displayer via the href attribute because the link element input was not sanitized.

CVSS v3:

  • Severity: Low
  • Score: 2
  • AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N