VYPR

Concrete CMS

by Concrete CMS

Source repositories

CVEs (190)

  • CVE-2021-40101HigNov 30, 2021
    risk 0.47cvss 7.2epss 0.03

    An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.

  • CVE-2021-40099HigSep 24, 2021
    risk 0.47cvss 7.2epss 0.02

    An issue was discovered in Concrete CMS through 8.5.5. Fetching the update json scheme over HTTP leads to remote code execution.

  • CVE-2026-18424HigSep 15, 2026
    risk 0.46cvss 7.1epss 0.00

    Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side Request Forgery iremote file import via cross-port reuse of a host's validated DNS pin. When multiple remote URLs share the same host, only the first `ValidatedRemoteUrl` is retained and reused for every later URL with…

  • CVE-2026-18423HigSep 15, 2026
    risk 0.46cvss 7.1epss 0.00

    Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs . An authenticated user holding only view permission on a single Express entity could therefore permanently delete, with no undo,…

  • CVE-2026-81902HigSep 14, 2026
    risk 0.46cvss 8.1epss 0.00

    Concrete CMS 9 through 9.5.2 did not validate a CSRF token in the orphaned block removal panel action (removeOrphanedBlocks). A remote attacker could craft a request that, when loaded by an authenticated user holding edit permission on the target page, deleted every block on…

  • CVE-2026-18426MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level edit-permission check on the Express Form block's control-management actions, which relied solely on CSRF token validation. Because the token is bound to the user and action rather than to a specific block, page, or…

  • CVE-2026-81898HigSep 15, 2026
    risk 0.42cvss —epss 0.00

    In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stored XSS in Express association views. A user able to submit an Address attribute could execute script in the session of any dashboard user who opened the…

  • CVE-2026-81910MedSep 11, 2026
    risk 0.42cvss 6.5epss 0.00

    Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values. Values submitted through the customizer (color channels and other style properties handled by ColorStyle and sibling Style classes such as…

  • CVE-2021-40109MedSep 27, 2021
    risk 0.42cvss 6.4epss 0.01

    A SSRF issue was discovered in Concrete CMS through 8.5.5. Users can access forbidden files on their local network. A user with permissions to upload files from external sites can upload a URL that redirects to an internal resource of any file type. The redirect is followed and…

  • CVE-2021-22950MedSep 23, 2021
    risk 0.42cvss 6.5epss 0.00

    Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for discovery: "Solar Security Research Team"

  • CVE-2026-81926MedSep 15, 2026
    risk 0.40cvss 6.1epss 0.00

    Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's duplicate-path confirmation dialog. The panel's check endpoint returned the submitted path unmodified in its JSON response, and client-side JavaScript inserted each…

  • CVE-2026-81895HigSep 15, 2026
    risk 0.40cvss 7.2epss 0.00

    In Concrete CMS before 9.5.3, the Document Library block stored the file-set identifiers submitted through fsID[] without validating them as integers, and when the block was configured with setMode set to any it concatenated each stored identifier directly into the file-set…

  • CVE-2026-18116MedSep 14, 2026
    risk 0.40cvss 6.1epss 0.00

    Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in the workflow approval and deletion notifications shown in the dashboard "Waiting For Me" block. A registered user permitted to add events to a calendar…

  • CVE-2026-8135HigMay 21, 2026
    risk 0.40cvss 7.2epss 0.00

    Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the ExpressEntryList block controller. An rogue administrator with privileges to add blocks to an area can bypass the intended protection mechanism (_fromCIF ===…

  • CVE-2026-8134HigMay 21, 2026
    risk 0.40cvss 7.2epss 0.01

    Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue administrator with composer form editing rights can exploit this to include…

  • CVE-2026-3452HigMar 4, 2026
    risk 0.40cvss 7.2epss 0.01

    Concrete CMS below version 9.4.8 is vulnerable to Remote Code Execution by stored PHP object injection into the Express Entry List block via the columns parameter. An authenticated administrator can store attacker-controlled serialized data in block configuration fields that…

  • CVE-2022-30120MedJun 24, 2022
    risk 0.40cvss 6.1epss 0.01

    XSS in /dashboard/blocks/stacks/view_details/ - old browsers only. When using an older browser with built-in XSS protection disabled, insufficient sanitation where built urls are outputted can be exploited for Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 to…

  • CVE-2022-30118MedJun 24, 2022
    risk 0.40cvss 6.1epss 0.01

    Title for CVE: XSS in /dashboard/system/express/entities/forms/save_control/[GUID]: old browsers only.Description: When using Internet Explorer with the XSS protection disabled, editing a form control in an express entities form for Concrete 8.5.7 and below as well as Concrete…

  • CVE-2021-40106MedSep 27, 2021
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Concrete CMS through 8.5.5. There is unauthenticated stored XSS in blog comments via the website field.

  • CVE-2021-40105MedSep 27, 2021
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Concrete CMS through 8.5.5. There is XSS via Markdown Comments.

Page 3 of 10