VYPR

Concrete5

by Concrete5

Source repositories

CVEs (166)

  • CVE-2017-7725MedApr 13, 2017
    risk 0.43cvss 6.1epss 0.03

    concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "canonical" URL on installation of concrete5 using the "Advanced Options" settings. Remote attackers can make a GET request with any domain name in the Host…

  • CVE-2026-30662MedMar 24, 2026
    risk 0.42cvss 6.5epss 0.00

    ConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. The 'download' method in 'concrete/controllers/backend/file.php' improperly manages memory when creating zip archives. It uses 'ZipArchive::addFromString' combined with…

  • CVE-2021-40109MedSep 27, 2021
    risk 0.42cvss 6.4epss 0.01

    A SSRF issue was discovered in Concrete CMS through 8.5.5. Users can access forbidden files on their local network. A user with permissions to upload files from external sites can upload a URL that redirects to an internal resource of any file type. The redirect is followed and…

  • CVE-2021-22950MedSep 23, 2021
    risk 0.42cvss 6.5epss 0.00

    Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for discovery: "Solar Security Research Team"

  • CVE-2017-8082MedApr 24, 2017
    risk 0.42cvss 6.5epss 0.01

    concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking an admin into viewing a malicious page involving the /tools/required/files/importers/imageeditor?fID=1&imgData= URI. This results…

  • CVE-2026-8135HigMay 21, 2026
    risk 0.40cvss 7.2epss 0.00

    Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the ExpressEntryList block controller. An rogue administrator with privileges to add blocks to an area can bypass the intended protection mechanism (_fromCIF ===…

  • CVE-2026-8134HigMay 21, 2026
    risk 0.40cvss 7.2epss 0.01

    Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue administrator with composer form editing rights can exploit this to include…

  • CVE-2026-3452HigMar 4, 2026
    risk 0.40cvss 7.2epss 0.01

    Concrete CMS below version 9.4.8 is vulnerable to Remote Code Execution by stored PHP object injection into the Express Entry List block via the columns parameter. An authenticated administrator can store attacker-controlled serialized data in block configuration fields that…

  • CVE-2022-43556MedDec 5, 2022
    risk 0.40cvss 6.1epss 0.01

    Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XSS in the text input field since the result dashboard page output is not sanitized. The Concrete CMS security team has ranked this 4.2 with CVSS v3.1 vector…

  • CVE-2022-30120MedJun 24, 2022
    risk 0.40cvss 6.1epss 0.01

    XSS in /dashboard/blocks/stacks/view_details/ - old browsers only. When using an older browser with built-in XSS protection disabled, insufficient sanitation where built urls are outputted can be exploited for Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 to…

  • CVE-2022-30119MedJun 24, 2022
    risk 0.40cvss 6.1epss 0.01

    XSS in /dashboard/reports/logs/view - old browsers only. When using Internet Explorer with the XSS protection disabled, insufficient sanitation where built urls are outputted can be exploited for Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2. This cannot be…

  • CVE-2022-30118MedJun 24, 2022
    risk 0.40cvss 6.1epss 0.01

    Title for CVE: XSS in /dashboard/system/express/entities/forms/save_control/[GUID]: old browsers only.Description: When using Internet Explorer with the XSS protection disabled, editing a form control in an express entities form for Concrete 8.5.7 and below as well as Concrete…

  • CVE-2021-41465MedOct 1, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in concrete/elements/collection_theme.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the rel parameter.

  • CVE-2021-41464MedOct 1, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the rel parameter.

  • CVE-2021-41463MedOct 1, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in toos/permissions/dialogs/access/entity/types/group_combination.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the cID parameter.

  • CVE-2021-41462MedOct 1, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the ctID parameter.

  • CVE-2021-41461MedOct 1, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the mode parameter.

  • CVE-2021-40106MedSep 27, 2021
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Concrete CMS through 8.5.5. There is unauthenticated stored XSS in blog comments via the website field.

  • CVE-2021-40105MedSep 27, 2021
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Concrete CMS through 8.5.5. There is XSS via Markdown Comments.

  • CVE-2020-11476HigJul 28, 2020
    risk 0.40cvss 7.2epss 0.03

    Concrete5 before 8.5.3 allows Unrestricted Upload of File with Dangerous Type such as a .phar file.

Page 3 of 9