← All vendors

concretecms

64 known vulnerabilities affecting concretecms products.

Products

concrete_cms 64

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-8327 Low 0.2% 4.3 Concrete CMS below 9.5.0 and below is vulnerable to password change without reau…
CVE-2026-81903 Low 0.2% 5.4 Concrete CMS versions 9.0.0 to 9.5.2 stored the Page Container icon value submit…
CVE-2026-7887 Low 0.2% 6.4 For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses …
CVE-2026-81919 Low 0.2% 4.3 Concrete CMS below 9.5.3 did not validate an anti-CSRF token on the block-arrang…
CVE-2026-7890 Low 0.2% 6.4 In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from…
CVE-2026-8139 Low 0.2% 5.4 Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page …
CVE-2026-8353 Low 0.1% 4.8 Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in t…
CVE-2026-81900 Low 0.1% 6.1 Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored widt…
CVE-2026-8245 Low 0.1% 5.4 Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination…
CVE-2026-8203 Low 0.1% 5.4 Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The control…
CVE-2026-8140 Low 0.1% 6.5 Concrete CMS 9.5.0 and below does not validate a CSRF token before processing re…
CVE-2026-7882 Low 0.1% 4.3 Concrete CMS 9.5.0 and below is vulnerable to unauthorized file deletion due to…
CVE-2026-8435 Low 0.1% 6.5 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a…
CVE-2026-8340 Low 0.1% 4.3 Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVers…
← Prev Page 2 of 2