VYPR

Concrete CMS

by Concrete CMS

Source repositories

CVEs (190)

  • CVE-2023-28476MedApr 28, 2023
    risk 0.35cvss 5.4epss 0.01

    Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Tags on uploaded files.

  • CVE-2023-28474MedApr 28, 2023
    risk 0.35cvss 5.4epss 0.01

    Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Saved Presets on search.

  • CVE-2023-28471MedApr 28, 2023
    risk 0.35cvss 5.4epss 0.01

    Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS via a container name.

  • CVE-2022-43686MedNov 14, 2022
    risk 0.35cvss 6.5epss 0.01

    In Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2, the authTypeConcreteCookieMap table can be filled up causing a denial of service (high load).

  • CVE-2021-22969MedNov 19, 2021
    risk 0.35cvss 5.3epss 0.01

    Concrete CMS (formerly concrete5) versions below 8.5.7 has a SSRF mitigation bypass using DNS Rebind attack giving an attacker the ability to fetch cloud IAAS (ex AWS) IAM keys.To fix this Concrete CMS no longer allows downloads from the local network and specifies the validated…

  • CVE-2021-40100MedSep 24, 2021
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Concrete CMS through 8.5.5. Stored XSS can occur in Conversations when the Active Conversation Editor is set to Rich Text.

  • CVE-2021-22953MedSep 23, 2021
    risk 0.35cvss 5.4epss 0.00

    A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security Research Team"

  • CVE-2021-22949MedSep 23, 2021
    risk 0.35cvss 5.4epss 0.00

    A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security CMS Research Team"

  • CVE-2021-28145MedMar 18, 2021
    risk 0.35cvss 5.4epss 0.01

    Concrete CMS (formerly concrete5) before 8.5.5 allows remote authenticated users to conduct XSS attacks via a crafted survey block. This requires at least Editor privileges.

  • CVE-2026-81913MedSep 11, 2026
    risk 0.34cvss —epss 0.01

    Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. An attacker can craft a single link on the site's own domain that sends a user to an arbitrary external site immediately after authentication, facilitating phishing and credential…

  • CVE-2026-81906MedSep 11, 2026
    risk 0.34cvss —epss 0.00

    Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete authentication and receive a session that…

  • CVE-2026-81905MedSep 11, 2026
    risk 0.34cvss —epss 0.00

    Concrete CMS below 9.5.3 stores user validation hashes for multiple purposes (email/registration validation, password reset, and persistent login) in a single table with a type column, but the redemption path resolves a hash by value alone and does not verify its type. As a…

  • CVE-2026-18121MedSep 11, 2026
    risk 0.34cvss —epss 0.00

    Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the caller is permitted to view the calendar that owns the requested event…

  • CVE-2026-81904MedSep 8, 2026
    risk 0.34cvss —epss 0.00

    Concrete CMS below 9.5.3 registered view assets for every sub-block of a Stack, Container, or layout area without checking whether the requesting user could view that sub-block. An unauthenticated visitor could recover configuration values emitted by a restricted sub-block's…

  • CVE-2022-43690MedNov 14, 2022
    risk 0.34cvss 6.3epss 0.01

    Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 did not use strict comparison for the legacy_salt so that limited authentication bypass could occur if using this functionality. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.

  • CVE-2026-85386MedSep 16, 2026
    risk 0.33cvss 6.1epss 0.00

    Concrete CMS before 9.5.4 did not sanitize XML and XSLT documents uploaded through a public Form Block file-upload question. Plain XML uploads were validated by file extension only and stored as publicly accessible files that were served inline from the application's own origin.…

  • CVE-2026-81925MedSep 15, 2026
    risk 0.33cvss 6.1epss 0.00

    Concrete CMS before 9.5.3 improperly neutralized a user-supplied custom date format when rendering conversation messages, resulting in reflected cross-site scripting. An attacker could execute arbitrary JavaScript in the browser of a user who was tricked into submitting a…

  • CVE-2026-81900MedSep 14, 2026
    risk 0.33cvss 6.1epss 0.00

    Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them into iframe HTML attributes without escaping or integer casting, resulting in stored cross-site scripting. A user with edit_block permission could inject an event…

  • CVE-2026-81907MedSep 11, 2026
    risk 0.33cvss —epss 0.00

    Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function (POST /index.php/dashboard/system/express/entities/delete_entries) because the controller records but does not enforce a failed CSRF token check, allowing the…

  • CVE-2026-68535MedSep 11, 2026
    risk 0.33cvss —epss 0.00

    Concrete CMS Area API's block-create endpoint in versions 9.2.0 to 9.5.2 did not invoke the block type controller's validate() method on submitted data, which, for file-referencing blocks such as hero_image and gallery, is where the referenced file is authorized against the…

Page 5 of 10