CVE-2025-2966: ConcreteCMS Content Block save cross site scripting
Published Mar 30, 2025
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
ConcreteCMS ConcreteCMS<=9.3.9
Event History
Mar 30, 2025
CVE Published
via MITRE·11:31 PM
Rejected
via MITRE·11:31 PM
Mar 31, 2025
Data Sourced
via NVD·12:15 AM
Description
Apr 4, 2025
Rejected
via MITRE·12:07 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-2966?
CVE-2025-2966 is classified as a problematic vulnerability that can lead to cross site scripting.
2
How do I fix CVE-2025-2966?
To fix CVE-2025-2966, update ConcreteCMS to version 9.4.0 or higher to mitigate the vulnerability.
3
What component is affected by CVE-2025-2966?
CVE-2025-2966 affects the Save function in the Content Block Handler component of ConcreteCMS.
4
Can CVE-2025-2966 be exploited remotely?
Yes, CVE-2025-2966 can be exploited remotely by manipulating the argument Source.
5
Which versions of ConcreteCMS are impacted by CVE-2025-2966?
CVE-2025-2966 impacts all versions of ConcreteCMS up to and including 9.3.9.