VYPR

Vendor CVEs

Concrete CMS

All CVEs

192 total · sorted by risk
  • CVE-2021-40109MedSep 27, 2021
    risk 0.42cvss 6.4epss 0.01

    A SSRF issue was discovered in Concrete CMS through 8.5.5. Users can access forbidden files on their local network. A user with permissions to upload files from external sites can upload a URL that redirects to an internal resource of any file type. The redirect is followed and…

  • CVE-2021-22950MedSep 23, 2021
    risk 0.42cvss 6.5epss 0.00

    Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for discovery: "Solar Security Research Team"

  • CVE-2026-81926MedSep 15, 2026
    risk 0.40cvss 6.1epss 0.00

    Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's duplicate-path confirmation dialog. The panel's check endpoint returned the submitted path unmodified in its JSON response, and client-side JavaScript inserted each…

  • CVE-2026-81895HigSep 15, 2026
    risk 0.40cvss 7.2epss 0.00

    In Concrete CMS before 9.5.3, the Document Library block stored the file-set identifiers submitted through fsID[] without validating them as integers, and when the block was configured with setMode set to any it concatenated each stored identifier directly into the file-set…

  • CVE-2026-18116MedSep 14, 2026
    risk 0.40cvss 6.1epss 0.00

    Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in the workflow approval and deletion notifications shown in the dashboard "Waiting For Me" block. A registered user permitted to add events to a calendar…

  • CVE-2026-8135HigMay 21, 2026
    risk 0.40cvss 7.2epss 0.00

    Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the ExpressEntryList block controller. An rogue administrator with privileges to add blocks to an area can bypass the intended protection mechanism (_fromCIF ===…

  • CVE-2026-8134HigMay 21, 2026
    risk 0.40cvss 7.2epss 0.01

    Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue administrator with composer form editing rights can exploit this to include…

  • CVE-2026-3452HigMar 4, 2026
    risk 0.40cvss 7.2epss 0.01

    Concrete CMS below version 9.4.8 is vulnerable to Remote Code Execution by stored PHP object injection into the Express Entry List block via the columns parameter. An authenticated administrator can store attacker-controlled serialized data in block configuration fields that…

  • CVE-2022-30120MedJun 24, 2022
    risk 0.40cvss 6.1epss 0.01

    XSS in /dashboard/blocks/stacks/view_details/ - old browsers only. When using an older browser with built-in XSS protection disabled, insufficient sanitation where built urls are outputted can be exploited for Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 to…

  • CVE-2022-30118MedJun 24, 2022
    risk 0.40cvss 6.1epss 0.01

    Title for CVE: XSS in /dashboard/system/express/entities/forms/save_control/[GUID]: old browsers only.Description: When using Internet Explorer with the XSS protection disabled, editing a form control in an express entities form for Concrete 8.5.7 and below as well as Concrete…

  • CVE-2021-40106MedSep 27, 2021
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Concrete CMS through 8.5.5. There is unauthenticated stored XSS in blog comments via the website field.

  • CVE-2021-40105MedSep 27, 2021
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Concrete CMS through 8.5.5. There is XSS via Markdown Comments.

  • CVE-2011-3183MedJan 14, 2020
    risk 0.40cvss 6.1epss 0.01

    A Cross-Site Scripting (XSS) vulnerability exists in the rcID parameter in Concrete CMS 5.4.1.1 and earlier.

  • CVE-2026-85387HigSep 16, 2026
    risk 0.39cvss 7.1epss 0.00

    Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-check the state of the account the token had been issued to. The resource server's authorization validator confirmed only that a token existed, had not expired, and had not…

  • CVE-2026-81908MedSep 11, 2026
    risk 0.39cvss —epss 0.00

    Concrete CMS 9.2.0 to 9.5.2 contain a missing authorization vulnerability in the REST API Groups list endpoint. The listGroups() method in concrete/src/Api/Controller/Groups.php registers a permissions checker callback that unconditionally returns true, so no per-object (tree…

  • CVE-2026-68527MedSep 10, 2026
    risk 0.38cvss —epss 0.00

    Concrete CMS versions 8.3.0 through 9.5.2 are vulnerable to an authorization bypass in the Calendar event edit dialog (concrete/controllers/dialog/event/edit.php). The dialog checked permissions against the calendar identifier supplied in the request rather than the calendar…

  • CVE-2026-2994MedMar 4, 2026
    risk 0.37cvss 6.8epss 0.00

    Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configuration via group_id parameter which can leads to a security bypass since changes are saved prior to checking the CSRF token. The Concrete CMS security team…

  • CVE-2026-87028MedSep 16, 2026
    risk 0.35cvss 6.5epss 0.00

    Concrete CMS 9 through 9.5.3 did not confirm that a board InstanceItem submitted to the custom-slot preview endpoint belonged to the board instance the requesting user was authorized to edit, and did not enforce page-view permission before generating page-backed summary content.…

  • CVE-2026-18422MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    Concrete CMS before 9.5.3 did not enforce a destination-side authorization check and did not validate a CSRF token in the multilingual page assignment backend action (Backend\Page\Multilingual::assign). As a result, an authenticated user who held the Edit Page Multilingual…

  • CVE-2026-81924MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in the theme page-template activation feature. The Dashboard theme Inspect controller's activate_files() action created PageTemplate records from attacker-supplied pageTemplates[] values without…

  • CVE-2026-81921MedSep 15, 2026
    risk 0.35cvss 5.4epss 0.00

    Concrete CMS 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token grant using the unmodified upstream League grant, which issued new access tokens from a valid refresh token without re-checking the associated account's active status. A user who obtained a refresh token while…

  • CVE-2026-81903MedSep 14, 2026
    risk 0.35cvss 5.4epss 0.00

    Concrete CMS versions 9.0.0 to 9.5.2 stored the Page Container icon value submitted through the dashboard without validating it against the set of known container icons. The unvalidated value was later concatenated into the src attribute of an img tag by a helper that did not…

  • CVE-2026-81911MedSep 11, 2026
    risk 0.35cvss 5.4epss 0.00

    Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot dialog. The custom_slot save_template endpoint authorizes the request only against the target board instance (canEditBoardContents()) and then persists the client-supplied…

  • CVE-2026-8435MedMay 21, 2026
    risk 0.35cvss 6.5epss 0.00

    Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC…

  • CVE-2026-7890MedMay 21, 2026
    risk 0.35cvss 6.4epss 0.00

    In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation enabling redirect-to-internal bypasses.  The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.1 with a…

  • CVE-2026-7887MedMay 21, 2026
    risk 0.35cvss 6.4epss 0.00

    For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status. A user with uIsActive=0 (suspended, banned, terminated employee) can still authenticate via OAuth and receive valid API tokens. The Concrete CMS security team gave this…

  • CVE-2026-8140MedMay 21, 2026
    risk 0.35cvss 6.5epss 0.00

    Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/install/download/. The download() method in concrete/controllers/single_page/dashboard/extend/install.php checks only the canInstallPackages() permission before…

  • CVE-2025-3153MedApr 3, 2025
    risk 0.35cvss 6.5epss 0.00

    Concrete CMS version 9 below 9.4.0RC2 and versions below 8.5.20 are vulnerable to CSRF and XSS in the Concrete CMS Address attribute because addresses are not properly sanitized in the output when a country is not specified.  Attackers are limited to individuals whom a site…

  • CVE-2023-44763MedOct 10, 2023
    risk 0.35cvss 5.4epss 0.01

    Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cross-Site Scripting (XSS). NOTE: the vendor's position is that a customer is supposed to know that "pdf" should be excluded from the allowed file types, even…

  • CVE-2023-44764MedOct 6, 2023
    risk 0.35cvss 5.4epss 0.01

    A Cross Site Scripting (XSS) vulnerability in Concrete CMS before 9.2.3 exists via the Name parameter during installation (aka Site of Installation or Settings).

  • CVE-2023-44762MedOct 6, 2023
    risk 0.35cvss 5.4epss 0.01

    A Cross Site Scripting (XSS) vulnerability in Concrete CMS from versions 9.2.0 to 9.2.2 allows an attacker to execute arbitrary code via a crafted script to the Tags from Settings - Tags.

  • CVE-2023-44761MedOct 6, 2023
    risk 0.35cvss 5.4epss 0.01

    Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS versions affected to 8.5.13 and below, and 9.0.0 through 9.2.1 allow a local attacker to execute arbitrary code via a crafted script to the Forms of the Data objects.

  • CVE-2023-28476MedApr 28, 2023
    risk 0.35cvss 5.4epss 0.01

    Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Tags on uploaded files.

  • CVE-2023-28474MedApr 28, 2023
    risk 0.35cvss 5.4epss 0.01

    Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Saved Presets on search.

  • CVE-2023-28471MedApr 28, 2023
    risk 0.35cvss 5.4epss 0.01

    Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS via a container name.

  • CVE-2022-43686MedNov 14, 2022
    risk 0.35cvss 6.5epss 0.01

    In Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2, the authTypeConcreteCookieMap table can be filled up causing a denial of service (high load).

  • CVE-2021-22969MedNov 19, 2021
    risk 0.35cvss 5.3epss 0.01

    Concrete CMS (formerly concrete5) versions below 8.5.7 has a SSRF mitigation bypass using DNS Rebind attack giving an attacker the ability to fetch cloud IAAS (ex AWS) IAM keys.To fix this Concrete CMS no longer allows downloads from the local network and specifies the validated…

  • CVE-2021-40100MedSep 24, 2021
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Concrete CMS through 8.5.5. Stored XSS can occur in Conversations when the Active Conversation Editor is set to Rich Text.

  • CVE-2021-22953MedSep 23, 2021
    risk 0.35cvss 5.4epss 0.00

    A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security Research Team"

  • CVE-2021-22949MedSep 23, 2021
    risk 0.35cvss 5.4epss 0.00

    A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security CMS Research Team"

  • CVE-2021-28145MedMar 18, 2021
    risk 0.35cvss 5.4epss 0.01

    Concrete CMS (formerly concrete5) before 8.5.5 allows remote authenticated users to conduct XSS attacks via a crafted survey block. This requires at least Editor privileges.

  • CVE-2026-81913MedSep 11, 2026
    risk 0.34cvss —epss 0.01

    Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. An attacker can craft a single link on the site's own domain that sends a user to an arbitrary external site immediately after authentication, facilitating phishing and credential…

  • CVE-2026-81906MedSep 11, 2026
    risk 0.34cvss —epss 0.00

    Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete authentication and receive a session that…

  • CVE-2026-81905MedSep 11, 2026
    risk 0.34cvss —epss 0.00

    Concrete CMS below 9.5.3 stores user validation hashes for multiple purposes (email/registration validation, password reset, and persistent login) in a single table with a type column, but the redemption path resolves a hash by value alone and does not verify its type. As a…

  • CVE-2026-18121MedSep 11, 2026
    risk 0.34cvss —epss 0.00

    Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the caller is permitted to view the calendar that owns the requested event…

  • CVE-2026-81904MedSep 8, 2026
    risk 0.34cvss —epss 0.00

    Concrete CMS below 9.5.3 registered view assets for every sub-block of a Stack, Container, or layout area without checking whether the requesting user could view that sub-block. An unauthenticated visitor could recover configuration values emitted by a restricted sub-block's…

  • CVE-2022-43690MedNov 14, 2022
    risk 0.34cvss 6.3epss 0.01

    Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 did not use strict comparison for the legacy_salt so that limited authentication bypass could occur if using this functionality. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.

  • CVE-2026-85386MedSep 16, 2026
    risk 0.33cvss 6.1epss 0.00

    Concrete CMS before 9.5.4 did not sanitize XML and XSLT documents uploaded through a public Form Block file-upload question. Plain XML uploads were validated by file extension only and stored as publicly accessible files that were served inline from the application's own origin.…

  • CVE-2026-81925MedSep 15, 2026
    risk 0.33cvss 6.1epss 0.00

    Concrete CMS before 9.5.3 improperly neutralized a user-supplied custom date format when rendering conversation messages, resulting in reflected cross-site scripting. An attacker could execute arbitrary JavaScript in the browser of a user who was tricked into submitting a…

  • CVE-2026-81900MedSep 14, 2026
    risk 0.33cvss 6.1epss 0.00

    Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them into iframe HTML attributes without escaping or integer casting, resulting in stored cross-site scripting. A user with edit_block permission could inject an event…