Filtered by vendor Portlandlabs Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-50807 1 Portlandlabs 1 Concrete Cms 2026-01-14 9.8 Critical
Concrete5 CMS version 9.1.3 contains an XPath injection vulnerability that allows attackers to manipulate URL path parameters with malicious payloads. Attackers can flood the system with crafted requests to potentially extract internal content paths and system information.