concretecms
64 known vulnerabilities affecting concretecms products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-8134 | Medium | 0.7% | 7.2 | Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the p… | |
| CVE-2026-8135 | Medium | 0.5% | 7.2 | Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to inse… | |
| CVE-2026-81901 | Medium | 0.3% | 8.7 | In Concrete CMS 9.2.0 through 9.5.2, the REST API page update endpoint (PUT /ccm… | |
| CVE-2026-18119 | Medium | 0.3% | 9.0 | Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Desig… | |
| CVE-2026-8350 | Medium | 0.3% | 8.8 | Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_… | |
| CVE-2026-81895 | Medium | 0.2% | 7.2 | In Concrete CMS before 9.5.3, the Document Library block stored the file-set ide… | |
| CVE-2026-81902 | Medium | 0.2% | 8.1 | Concrete CMS 9 through 9.5.2 did not validate a CSRF token in the orphaned block… | |
| CVE-2026-8421 | Medium | 0.2% | 8.8 | Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_packag… | |
| CVE-2026-8426 | Medium | 0.2% | 8.8 | Concrete CMS 9.5.0 and below does not validate a CSRF token before processing re… | |
| CVE-2026-8409 | Medium | 0.1% | 8.8 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a… | |
| CVE-2026-8410 | Medium | 0.1% | 8.8 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a… | |
| CVE-2026-8428 | Medium | 0.1% | 8.8 | Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.ph… | |
| CVE-2026-8411 | Medium | 0.1% | 8.8 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a… | |
| CVE-2026-8412 | Medium | 0.1% | 8.8 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a… | |
| CVE-2026-8413 | Medium | 0.1% | 8.8 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a… | |
| CVE-2026-8414 | Medium | 0.1% | 8.8 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a… | |
| CVE-2026-8415 | Medium | 0.1% | 8.8 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a… | |
| CVE-2026-8416 | Medium | 0.1% | 8.8 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a… | |
| CVE-2026-8427 | Medium | 0.1% | 8.8 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a… | |
| CVE-2026-8432 | Medium | 0.1% | 8.8 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a… | |
| CVE-2026-8433 | Medium | 0.1% | 8.8 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a… | |
| CVE-2026-8434 | Medium | 0.1% | 8.8 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a… | |
| CVE-2026-8417 | Medium | 0.1% | 8.8 | Concrete CMS 9.5.0 and below does not validate a CSRF token before processing re… | |
| CVE-2026-6826 | Low | 1.5% | 5.3 | Concrete CMS 9.5.0 and below is vulnerable to unauthenticated file usage disclo… | |
| CVE-2026-8237 | Low | 0.6% | 5.3 | Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversat… | |
| CVE-2026-8236 | Low | 0.5% | 4.3 | Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authe… | |
| CVE-2026-81917 | Low | 0.4% | 5.4 | Concrete CMS below 9.5.3 does not apply HTML output escaping to the file descrip… | |
| CVE-2026-81911 | Low | 0.3% | 5.4 | Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom… | |
| CVE-2026-81918 | Low | 0.3% | 4.8 | Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field i… | |
| CVE-2026-81916 | Low | 0.3% | 4.3 | Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry… | |
| CVE-2026-81927 | Low | 0.3% | 5.4 | Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability … | |
| CVE-2026-7886 | Low | 0.3% | 4.3 | Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage v… | |
| CVE-2026-81896 | Low | 0.3% | 5.4 | Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Fo… | |
| CVE-2026-81894 | Low | 0.2% | 5.4 | Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Script… | |
| CVE-2026-81910 | Low | 0.2% | 6.5 | Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SS… | |
| CVE-2026-81922 | Low | 0.2% | 2.7 | Concrete CMS before 9.5.3 did not enforce a per-page authorization check when re… | |
| CVE-2026-81923 | Low | 0.2% | 2.7 | In Concrete CMS before 9.5.3, the SEO Bulk Update Meta Tags editor did not check… | |
| CVE-2026-8347 | Low | 0.2% | 4.3 | Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level i… | |
| CVE-2026-7879 | Low | 0.2% | 5.3 | In Concrete CMS 9.5.0 and below, the submit_password() method in concrete/contr… | |
| CVE-2026-8204 | Low | 0.2% | 5.3 | Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calend… | |
| CVE-2026-8205 | Low | 0.2% | 5.3 | Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calend… | |
| CVE-2026-81921 | Low | 0.2% | 5.4 | Concrete CMS 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token grant using… | |
| CVE-2026-7881 | Low | 0.2% | 4.3 | Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDO… | |
| CVE-2026-8238 | Low | 0.2% | 5.3 | Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversat… | |
| CVE-2026-8239 | Low | 0.2% | 5.3 | Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversat… | |
| CVE-2026-8240 | Low | 0.2% | 5.3 | Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disc… | |
| CVE-2026-8337 | Low | 0.2% | 5.3 | Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable,… | |
| CVE-2026-81920 | Low | 0.2% | 4.3 | Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the das… | |
| CVE-2026-81897 | Low | 0.2% | 5.4 | In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities… | |
| CVE-2026-8197 | Low | 0.2% | 4.8 | Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration n… |
Page 1 of 2
Next →