CVE-2025-2968: ConcreteCMS Feature Block save cross site scripting
Published Mar 31, 2025
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
ConcreteCMS ConcreteCMS<=9.3.9
Event History
Mar 31, 2025
CVE Published
via MITRE·12:31 AM
Rejected
via MITRE·12:31 AM
Data Sourced
via NVD·01:15 AM
Description
Apr 4, 2025
Rejected
via MITRE·12:10 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-2968?
CVE-2025-2968 is classified as a problematic vulnerability that enables cross-site scripting in ConcreteCMS.
2
How do I fix CVE-2025-2968?
To mitigate CVE-2025-2968, upgrade ConcreteCMS to version 9.4.0 or later, where the vulnerability is addressed.
3
What component is affected by CVE-2025-2968?
CVE-2025-2968 affects the Feature Block Handler component in ConcreteCMS.
4
What types of attacks are associated with CVE-2025-2968?
CVE-2025-2968 allows attackers to perform cross-site scripting (XSS) attacks due to improper handling of user input.
5
Which versions of ConcreteCMS are vulnerable to CVE-2025-2968?
ConcreteCMS versions up to and including 9.3.9 are vulnerable to CVE-2025-2968.