VYPR

Concrete CMS

by Concrete CMS

Source repositories

CVEs (190)

  • CVE-2023-28475MedApr 28, 2023
    risk 0.33cvss 6.1epss 0.01

    Concrete CMS (previously concrete5) versions 8.5.12 and below, and versions 9.0 through 9.1.3 is vulnerable to Reflected XSS on the Reply form because msgID was not sanitized.

  • CVE-2022-43968MedNov 14, 2022
    risk 0.33cvss 6.1epss 0.01

    Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the dashboard icons due to un-sanitized output. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.

  • CVE-2022-43967MedNov 14, 2022
    risk 0.33cvss 6.1epss 0.01

    Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the multilingual report due to un-sanitized output. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.

  • CVE-2022-43694MedNov 14, 2022
    risk 0.33cvss 6.1epss 0.01

    Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the image manipulation library due to un-sanitized output.

  • CVE-2022-43692MedNov 14, 2022
    risk 0.33cvss 6.1epss 0.01

    Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS - user can cause an administrator to trigger reflected XSS with a url if the targeted administrator is using an old browser that lacks XSS protection. Remediate by updating…

  • CVE-2026-68528MedSep 11, 2026
    risk 0.32cvss —epss 0.00

    Concrete CMS RSS Displayer block below version 9.5.3 rendered remote feed item titles without HTML escaping, resulting in stored cross-site scripting. An attacker able to control a title in a syndicated feed could execute script in the site origin for any visitor to the…

  • CVE-2026-18122MedSep 11, 2026
    risk 0.32cvss —epss 0.00

    Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization; the Concrete CMS REST API's Express entry collection endpoint disabled the per-entry view permission check. An OAuth token with read scope for an Express…

  • CVE-2026-18120MedSep 16, 2026
    risk 0.31cvss 5.9epss 0.00

    Concrete CMS before 9.5.3 exposed a legacy Express entry search endpoint that returned entry result JSON without invoking the canViewExpressEntries() permission check applied by the normal dashboard and CSV Export flow. An unauthenticated visitor who knew or discovered an…

  • CVE-2026-81909MedSep 11, 2026
    risk 0.31cvss —epss 0.00

    Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the block alias route (Process::alias() in concrete/controllers/backend/block/process.php).It does not verify that the referenced block is genuinely orphaned on the target page, nor that the caller holds any…

  • CVE-2026-8353MedMay 22, 2026
    risk 0.31cvss 4.8epss 0.00

    Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inject arbitrary JavaScript that executes in the context of any authenticated user visiting the affected account pages. This can lead to session hijacking,…

  • CVE-2024-7512MedAug 12, 2024
    risk 0.31cvss 4.8epss 0.00

    Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in Board instances. A rogue administrator could inject malicious code. The Concrete CMS security team gave this vulnerability a CVSS 4.0 Score of 4.6 with vector:…

  • CVE-2023-44760MedOct 23, 2023
    risk 0.31cvss 4.8epss 0.01

    Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS v.9.2.1 allow an attacker to execute arbitrary code via a crafted script to the Header and Footer Tracking Codes of the SEO & Statistics. NOTE: the vendor disputes this because these header/footer changes can…

  • CVE-2023-44766MedOct 6, 2023
    risk 0.31cvss 4.8epss 0.01

    A Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 allows an attacker to execute arbitrary code via a crafted script to the SEO - Extra from Page Settings. NOTE: the vendor disputes this because this SEO-related header change can only be made by an admin, and…

  • CVE-2026-81912MedSep 11, 2026
    risk 0.30cvss —epss 0.00

    Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature. The dashboard/users/groups/bulkupdate/confirm() endpoint moved the selected group tree nodes without validating an action token, so a state-changing group move could be…

  • CVE-2023-28477MedApr 28, 2023
    risk 0.29cvss 5.5epss 0.01

    Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to stored XSS on API Integrations via the name parameter.

  • CVE-2026-81927MedSep 15, 2026
    risk 0.28cvss 5.4epss 0.00

    Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling. When SVG processing was set to the non-default "Reject files containing potentially harmful elements" mode (concrete.file_manager.images.svg_sanitization.action = reject),…

  • CVE-2026-81897MedSep 15, 2026
    risk 0.28cvss 5.4epss 0.00

    In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not validate the anti-CSRF token. By causing an authenticated administrator to submit a forged cross-site request, a remote attacker without credentials could write…

  • CVE-2026-81896MedSep 15, 2026
    risk 0.28cvss 5.4epss 0.00

    Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Form block question labels when rendering them as column headers in the Dashboard Form Submissions report (concrete/single_pages/dashboard/reports/forms/legacy.php). a rogue editor could store markup…

  • CVE-2026-81894MedSep 15, 2026
    risk 0.28cvss 5.4epss 0.00

    Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-image Caption field because the bundled Magnific Popup lightbox script (concrete/js/features/imagery/frontend.js) re-parses the attribute-decoded caption as HTML…

  • CVE-2026-81917MedSep 11, 2026
    risk 0.28cvss 5.4epss 0.00

    Concrete CMS below 9.5.3 does not apply HTML output escaping to the file description and tags fields when rendering the Document Library block, so a user with permission to edit file properties could store a script payload that executed in the browser of any visitor to a page…

Page 6 of 10