{"id":"CVE-2015-3989","aliases":[],"url":"https://o3.security/vulnerability/CVE-2015-3989","summary":"concrete5 vulnerable to Cross-site Scripting","details":"Multiple cross-site scripting (XSS) vulnerabilities in concrete5 before 5.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to private messages or other unspecified vectors.","published":"2022-05-17T03:29:56Z","modified":"2025-04-14T20:12:17.732181Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"concrete5/concrete5","fixedVersion":"5.7.4"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-3989"},{"type":"WEB","url":"https://documentation.concretecms.org/developers/introduction/version-history/5-7-4-release-notes"},{"type":"PACKAGE","url":"https://github.com/concretecms/concretecms"},{"type":"WEB","url":"https://web.archive.org/web/20200228094356/http://www.securityfocus.com/bid/74699"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-04-14T20:12:17.732181Z"}}