CVE-2025-2971: ConcreteCMS List Block cross site scripting
Published Mar 31, 2025
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
ConcreteCMS ConcreteCMS<=9.3.9
Event History
Mar 31, 2025
CVE Published
via MITRE·02:00 AM
Rejected
via MITRE·02:00 AM
Data Sourced
via NVD·02:15 AM
Description
Apr 7, 2025
Rejected
via MITRE·10:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-2971?
CVE-2025-2971 is classified as problematic, indicating a significant security risk.
2
How do I fix CVE-2025-2971?
To fix CVE-2025-2971, upgrade ConcreteCMS to version 9.4.0 or later.
3
What type of vulnerability is CVE-2025-2971?
CVE-2025-2971 is a cross-site scripting (XSS) vulnerability affecting the List Block Handler component.
4
What versions of ConcreteCMS are affected by CVE-2025-2971?
CVE-2025-2971 affects all versions of ConcreteCMS up to and including 9.3.9.
5
Can CVE-2025-2971 be exploited remotely?
Yes, CVE-2025-2971 can be exploited remotely, allowing attackers to manipulate user input in the affected component.