VendorsConcrete CMSconcrete_cmsall versions
Vulnerabilities

Concrete CMS Concrete CMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

195CVEs
CVE-2022-21829
Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which could lead to an RCE. Fixed by enforcing ‘concrete_secure’ instead of ‘concrete’. Concrete now only makes requests over https even a request comes in via http. Concrete CMS security team ranked this 8 with CVSS v3.1 vector: AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Credit goes to Anna for reporting HackerOne 1482520.
Published 2022-06-24 · Modified
9.8EPSS 0.018
CVE-2021-40098
An issue was discovered in Concrete CMS through 8.5.5. Path Traversal leading to RCE via external form by adding a regular expression.
Published 2021-09-27 · Modified
9.8EPSS 0.016
CVE-2023-48648
Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creation functions (such as the Mkdir() function) gives universal access (0777) to created folders by default. Excessive permissions can be granted when creating a directory with permissions greater than 0755 or when the permissions argument is not specified.
Published 2023-11-17 · Modified
9.8EPSS 0.012
CVE-2021-22958
A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the limitations in place for localhost allowing interaction with local services. Impact can vary depending on services exposed.CVSSv2.0 AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
Published 2021-10-07 · Modified
9.8EPSS 0.012
CVE-2026-85385
Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone Field
Published 2026-09-16 · Analyzed
9.6EPSS 0.005
CVE-2026-8134
Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemplate Path Traversal leading to PHP File Inclusion
Published 2026-05-21 · Analyzed
9.4EPSS 0.011
CVE-2022-30117
Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 allow traversal in /index.php/ccm/system/file/upload which could result in an Arbitrary File Delete exploit. This was remediated by sanitizing /index.php/ccm/system/file/upload to ensure Concrete doesn’t allow traversal and by changing isFullChunkFilePresent to have an early false return when input doesn't match expectations.Concrete CMS Security team ranked this 5.8 with CVSS v3.1 vector AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H. Credit to Siebene for reporting.
Published 2022-06-24 · Modified
9.1EPSS 0.021
CVE-2021-40102
An issue was discovered in Concrete CMS through 8.5.5. Arbitrary File deletion can occur via PHAR deserialization in is_dir (PHP Object Injection associated with the __wakeup magic method).
Published 2021-09-24 · Modified
9.1EPSS 0.013
CVE-2020-11476
Concrete5 before 8.5.3 allows Unrestricted Upload of File with Dangerous Type such as a .phar file.
Published 2020-07-28 · Modified
9.0EPSS 0.029
CVE-2020-24986
Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File Manager. It is possible to modify site configuration to upload the PHP file and execute arbitrary commands.
Published 2020-09-04 · Modified
9.0EPSS 0.020
CVE-2026-18119
Concrete CMS below 9.5.3 is vulnerable to Stored XSS via unsanitized inline block custom style values
Published 2026-09-14 · Analyzed
9.0EPSS 0.003
CVE-2026-3452
Concrete CMS below 9.4.8 is vulnerable to stored deserialization leading to RCE in the Express Entry List block.
Published 2026-03-04 · Analyzed
8.9EPSS 0.009
CVE-2026-8135
Concrete CMS 9.5.0 and below is vulnerable to RCE due to insecure deserialization occurring in the ExpressEntryList block controller.
Published 2026-05-21 · Analyzed
8.9EPSS 0.007
CVE-2021-40097
An issue was discovered in Concrete CMS through 8.5.5. Authenticated path traversal leads to to remote code execution via uploaded PHP code, related to the bFilename parameter.
Published 2021-09-27 · Modified
8.8EPSS 0.025
CVE-2021-22966
Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below. If a group is granted "view" permissions on the bulkupdate page, then users in that group can escalate to being an administrator with a specially crafted curl. Fixed by adding a check for group permissions before allowing a group to be moved. Concrete CMS Security team CVSS scoring: 7.1 AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HCredit for discovery: "Adrian Tiron from FORTBRIDGE ( https://www.fortbridge.co.uk/ )"This fix is also in Concrete version 9.0.0
Published 2021-11-19 · Modified
8.8EPSS 0.010
CVE-2015-4724
SQL injection vulnerability in Concrete5 5.7.3.1.
Published 2017-09-07 · Modified
8.8EPSS 0.008
CVE-2021-22954
A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an attacker to make requests on behalf of other users.
Published 2022-02-09 · Modified
8.8EPSS 0.005
CVE-2021-40108
An issue was discovered in Concrete CMS through 8.5.5. The Calendar is vulnerable to CSRF. ccm_token is not verified on the ccm/calendar/dialogs/event/add/save endpoint.
Published 2021-09-27 · Modified
8.8EPSS 0.005
CVE-2022-43693
Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for users of Concrete who use the "out of the box" core OAuth.
Published 2022-11-14 · Modified
8.8EPSS 0.005
CVE-2026-8350
Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to privilege escalation to Administrative Group
Published 2026-05-21 · Analyzed
8.8EPSS 0.005
CVE-2026-8421
Concrete CMS 9.5.0 and below is vulnerable to CSRF on install_package() with conditional token bypass leading to RCE
Published 2026-05-21 · Analyzed
8.8EPSS 0.003
CVE-2026-8426
Concrete CMS 9.5.0 and below is vulnerable to CSRF on prepare_remote_upgrade() leading to one-request RCE via package overwrite
Published 2026-05-21 · Analyzed
8.8EPSS 0.003
CVE-2026-8410
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete
Published 2026-05-21 · Analyzed
8.8EPSS 0.002
CVE-2026-8409
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete
Published 2026-05-21 · Analyzed
8.8EPSS 0.002
CVE-2026-8434
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple()
Published 2026-05-21 · Analyzed
8.8EPSS 0.002
CVE-2026-8433
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan()
Published 2026-05-21 · Analyzed
8.8EPSS 0.002
CVE-2026-8432
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star()
Published 2026-05-21 · Analyzed
8.8EPSS 0.002
CVE-2026-8415
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder
Published 2026-05-21 · Analyzed
8.8EPSS 0.002
CVE-2026-8427
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id)
Published 2026-05-21 · Analyzed
8.8EPSS 0.002
CVE-2026-8411
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete
Published 2026-05-21 · Analyzed
8.8EPSS 0.002
CVE-2026-8416
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id)
Published 2026-05-21 · Analyzed
8.8EPSS 0.002
CVE-2026-8414
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate
Published 2026-05-21 · Analyzed
8.8EPSS 0.002
CVE-2026-8413
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design
Published 2026-05-21 · Analyzed
8.8EPSS 0.002
CVE-2026-8412
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache
Published 2026-05-21 · Analyzed
8.8EPSS 0.002
CVE-2026-8417
Concrete CMS 9.5.0 and below is vulnerable to CSRF in do_update() in the package update controller
Published 2026-05-21 · Analyzed
8.8EPSS 0.002
CVE-2026-8428
CSRF token is not validated in the core CMS update controller for Concrete CMS 9.5.0 and below
Published 2026-05-21 · Analyzed
8.8EPSS 0.002
CVE-2026-81901
Concrete CMS 9.2.0 to 9.5.2 is vulnerable to stored XSS due to missing authorization in the `PUT /pages/{cID}` endpoint
Published 2026-09-14 · Analyzed
8.7EPSS 0.004
CVE-2026-18110
Concrete CMS 9.0.0 through 9.5.2 is vulnerable to missing authorization in the user selector autocomplete endpoint (/ccm/system/user/autocomplete), allowing an unauthenticated attacker to retrieve the complete backend user directory — internal ID, username
Published 2026-09-15 · Analyzed
8.7EPSS 0.003
CVE-2026-81895
Concrete CMS 9.5.2 and below is vulnerable to Stored SQL Injection in Concrete CMS Document Library Block via `fsID[]` in `setMode=any`
Published 2026-09-15 · Analyzed
8.5EPSS 0.005
CVE-2026-81894
Concrete CMS 9.5.2 and below is vulnerable to Stored DOM-based Cross-site Scripting (XSS) in the Gallery block image Caption field
Published 2026-09-15 · Analyzed
8.5EPSS 0.002
1 / 5Next →