← All vendors

concretecms

64 known vulnerabilities affecting concretecms products.

Products

concrete_cms 64

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-8134 Medium 0.7% 7.2 Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the p…
CVE-2026-8135 Medium 0.5% 7.2 Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to inse…
CVE-2026-81901 Medium 0.3% 8.7 In Concrete CMS 9.2.0 through 9.5.2, the REST API page update endpoint (PUT /ccm…
CVE-2026-18119 Medium 0.3% 9.0 Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Desig…
CVE-2026-8350 Medium 0.3% 8.8 Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_…
CVE-2026-81895 Medium 0.2% 7.2 In Concrete CMS before 9.5.3, the Document Library block stored the file-set ide…
CVE-2026-81902 Medium 0.2% 8.1 Concrete CMS 9 through 9.5.2 did not validate a CSRF token in the orphaned block…
CVE-2026-8421 Medium 0.2% 8.8 Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_packag…
CVE-2026-8426 Medium 0.2% 8.8 Concrete CMS 9.5.0 and below does not validate a CSRF token before processing re…
CVE-2026-8409 Medium 0.1% 8.8 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a…
CVE-2026-8410 Medium 0.1% 8.8 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a…
CVE-2026-8428 Medium 0.1% 8.8 Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.ph…
CVE-2026-8411 Medium 0.1% 8.8 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a…
CVE-2026-8412 Medium 0.1% 8.8 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a…
CVE-2026-8413 Medium 0.1% 8.8 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a…
CVE-2026-8414 Medium 0.1% 8.8 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a…
CVE-2026-8415 Medium 0.1% 8.8 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a…
CVE-2026-8416 Medium 0.1% 8.8 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a…
CVE-2026-8427 Medium 0.1% 8.8 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a…
CVE-2026-8432 Medium 0.1% 8.8 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a…
CVE-2026-8433 Medium 0.1% 8.8 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a…
CVE-2026-8434 Medium 0.1% 8.8 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a…
CVE-2026-8417 Medium 0.1% 8.8 Concrete CMS 9.5.0 and below does not validate a CSRF token before processing re…
CVE-2026-6826 Low 1.5% 5.3 Concrete CMS 9.5.0 and below  is vulnerable to unauthenticated file usage disclo…
CVE-2026-8237 Low 0.6% 5.3 Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversat…
CVE-2026-8236 Low 0.5% 4.3 Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authe…
CVE-2026-81917 Low 0.4% 5.4 Concrete CMS below 9.5.3 does not apply HTML output escaping to the file descrip…
CVE-2026-81911 Low 0.3% 5.4 Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom…
CVE-2026-81918 Low 0.3% 4.8 Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field i…
CVE-2026-81916 Low 0.3% 4.3 Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry…
CVE-2026-81927 Low 0.3% 5.4 Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability …
CVE-2026-7886 Low 0.3% 4.3 Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage v…
CVE-2026-81896 Low 0.3% 5.4 Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Fo…
CVE-2026-81894 Low 0.2% 5.4 Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Script…
CVE-2026-81910 Low 0.2% 6.5 Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SS…
CVE-2026-81922 Low 0.2% 2.7 Concrete CMS before 9.5.3 did not enforce a per-page authorization check when re…
CVE-2026-81923 Low 0.2% 2.7 In Concrete CMS before 9.5.3, the SEO Bulk Update Meta Tags editor did not check…
CVE-2026-8347 Low 0.2% 4.3 Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level i…
CVE-2026-7879 Low 0.2% 5.3 In Concrete CMS 9.5.0 and below,  the submit_password() method in concrete/contr…
CVE-2026-8204 Low 0.2% 5.3 Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calend…
CVE-2026-8205 Low 0.2% 5.3 Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calend…
CVE-2026-81921 Low 0.2% 5.4 Concrete CMS 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token grant using…
CVE-2026-7881 Low 0.2% 4.3 Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDO…
CVE-2026-8238 Low 0.2% 5.3 Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversat…
CVE-2026-8239 Low 0.2% 5.3 Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversat…
CVE-2026-8240 Low 0.2% 5.3 Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disc…
CVE-2026-8337 Low 0.2% 5.3 Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable,…
CVE-2026-81920 Low 0.2% 4.3 Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the das…
CVE-2026-81897 Low 0.2% 5.4 In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities…
CVE-2026-8197 Low 0.2% 4.8 Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration n…
Page 1 of 2 Next →