VendorsConcrete CMSconcrete_cmsany version
Vulnerabilities

Concrete CMS Concrete CMS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

179CVEs
CVE-2026-81902
Concrete CMS 9.0.0 to 9.5.2 is vulnerable to CSRF on Orphan Block Cleanup
Published 2026-09-14 · Analyzed
8.1EPSS 0.002
CVE-2026-81897
Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via Express form Text control save_control
Published 2026-09-15 · Analyzed
7.7EPSS 0.002
CVE-2021-22970
Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system to be vulnerable toa. SSRF attacks on the private LAN servers by reading files from the local LAN. An attacker can pivot in the private LAN and exploit local network appsandb. SSRF Mitigation Bypass through DNS RebindingConcrete CMS security team gave this a CVSS score of 3.5 AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:NConcrete CMS is maintaining Concrete version 8.5.x until 1 May 2022 for security fixes.This CVE is shared with HackerOne Reports https://hackerone.com/reports/1364797 and https://hackerone.com/reports/1360016Reporters: Adrian Tiron from FORTBRIDGE (https://www.fortbridge.co.uk/ ) and Bipul Jaiswal
Published 2021-11-19 · Modified
7.5EPSS 0.015
CVE-2021-40103
An issue was discovered in Concrete CMS through 8.5.5. Path Traversal can lead to Arbitrary File Reading and SSRF.
Published 2021-09-27 · Modified
7.5EPSS 0.015
CVE-2021-40104
An issue was discovered in Concrete CMS through 8.5.5. There is an SVG sanitizer bypass.
Published 2021-09-27 · Modified
7.5EPSS 0.014
CVE-2021-22967
In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to a Conversation.To remediate this, a check was added to verify a user has permissions to view files before attaching the files to a message in "add / edit message”.Concrete CMS security team gave this a CVSS v3.1 score of 4.3 AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NCredit for discovery Adrian H
Published 2021-11-19 · Modified
7.5EPSS 0.011
CVE-2021-22951
Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.7. Concrete CMS now checks to see if a file has a password in view_inline and, if it does, the file is not rendered.For version 8.5.6, the following mitigations were put in place a. restricting file types for view_inline to images only b. putting a warning in the file manager to advise users.Credit for discovery: "Solar Security Research Team"Concrete CMS security team CVSS scoring is 5.3: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NThis fix is also in Concrete version 9.0.0
Published 2021-11-19 · Modified
7.5EPSS 0.011
CVE-2026-8140
Concrete CMS 9.5.0 and below is vulnerable to CSRF on download() in the package install controller
Published 2026-05-21 · Analyzed
7.5EPSS 0.002
CVE-2026-81900
Concrete CMS before 9.5.3 is vulnerable to Stored XSS in the YouTube block (vWidth/vHeight)
Published 2026-09-14 · Analyzed
7.3EPSS 0.003
CVE-2026-8197
Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration name
Published 2026-05-21 · Analyzed
7.3EPSS 0.003
CVE-2026-85386
Concrete CMS before 9.5.4 stored is vulneratble to cross-site scripting via unauthenticated XML/XSLT file upload in the Form Block
Published 2026-09-16 · Analyzed
7.3EPSS 0.002
CVE-2026-8203
Concrete CMS 9.5.0 and below has Stored XSS on the height parameter
Published 2026-05-21 · Analyzed
7.3EPSS 0.002
CVE-2026-18116
Concrete CMS 8.3.0 to 9.5.2 is vulnerable to Stored XSS in Calendar Event Name via Workflow Approval Notifications
Published 2026-09-14 · Analyzed
7.3EPSS 0.002
CVE-2021-36766
Concrete5 through 8.5.5 deserializes Untrusted Data. The vulnerable code is located within the controllers/single_page/dashboard/system/environment/logging.php Logging::update_logging() method. User input passed through the logFile request parameter is not properly sanitized before being used in a call to the file_exists() PHP function. This can be exploited by malicious users to inject arbitrary PHP objects into the application scope (PHP Object Injection via phar:// stream wrapper), allowing them to carry out a variety of attacks, such as executing arbitrary PHP code.
Published 2021-07-27 · Modified
7.2EPSS 0.037
CVE-2021-22968
A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Concrete CMS (concrete5) versions 8.5.6 and below.The external file upload feature stages files in the public directory even if they have disallowed file extensions. They are stored in a directory with a random name, but it's possible to stall the uploads and brute force the directory name. You have to be an admin with the ability to upload files, but this bug gives you the ability to upload restricted file types and execute them depending on server configuration.To fix this, a check for allowed file extensions was added before downloading files to a tmp directory.Concrete CMS Security Team gave this a CVSS v3.1 score of 5.4 AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:H/A:NThis fix is also in Concrete version 9.0.0
Published 2021-11-19 · Modified
7.2EPSS 0.032
CVE-2021-40101
An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.
Published 2021-11-30 · Modified
7.2EPSS 0.026
CVE-2021-40099
An issue was discovered in Concrete CMS through 8.5.5. Fetching the update json scheme over HTTP leads to remote code execution.
Published 2021-09-24 · Modified
7.2EPSS 0.021
CVE-2026-85387
Concrete CMS before 9.5.4 allows a deactivated user to retain OAuth-authenticated REST API access
Published 2026-09-16 · Analyzed
7.1EPSS 0.002
CVE-2026-18423
Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs allowing an authenticated user with permission on one Express entity to delete or rename saved search pres
Published 2026-09-15 · Analyzed
7.1EPSS 0.002
CVE-2026-18424
Concrete CMS 9.0.0 to 9.5.2 is vulnerable to SSRF protection bypass in remote file import when multiple URLs share a host but use different ports
Published 2026-09-15 · Analyzed
7.1EPSS 0.002
CVE-2026-81907
Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) vin Express delete_entries allowing mass deletion of all entity records
Published 2026-09-11 · Analyzed
7.1EPSS 0.001
CVE-2026-81903
Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS via Page Container icon
Published 2026-09-14 · Analyzed
7.0EPSS 0.003
CVE-2026-6826
Concrete 9.5.0 and below has file usage disclosure via missing permission check in Usage controller
Published 2026-05-21 · Analyzed
6.9EPSS 0.013
CVE-2026-2994
Concrete CMS below 9.4.8 is vulnerable to CSRF by a Rogue Admin using the Anti-Spam Allowlist Group
Published 2026-03-04 · Analyzed
6.8EPSS 0.002
CVE-2022-43686
In Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2, the authTypeConcreteCookieMap table can be filled up causing a denial of service (high load).
Published 2022-11-14 · Modified
6.5EPSS 0.011
CVE-2026-18422
Concrete CMS below 9.5.3 Multilingual Page Assign Action Lacks Destination Authorization and CSRF Token Validation
Published 2026-09-15 · Analyzed
6.5EPSS 0.004
CVE-2021-22950
Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for discovery: "Solar Security Research Team"
Published 2021-09-23 · Modified
6.5EPSS 0.004
CVE-2026-81910
Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values
Published 2026-09-11 · Analyzed
6.5EPSS 0.004
CVE-2026-87028
Cross-Board IDOR in the Board Custom Slot Preview in Concrete CMS 9.0.0 through 9.5.3 Discloses Restricted Page Summary Fields
Published 2026-09-16 · Analyzed
6.5EPSS 0.004
CVE-2026-81924
Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Theme Page Template Activation
Published 2026-09-15 · Analyzed
6.5EPSS 0.002
CVE-2026-18426
Concrete CMS 9.0.0 to 9.5.2 Express Form block missing authorization allows an authenticated editor to modify Express Forms they cannot edit
Published 2026-09-15 · Analyzed
6.5EPSS 0.002
CVE-2025-3153
Concrete CMS version 9 below 9.4.0RC2 and versions below 8.5.20 - CSRF and XSS in Concrete CMS Custom Address attribute
Published 2025-04-03 · Analyzed
6.5EPSS 0.002
CVE-2026-8435
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion()
Published 2026-05-21 · Analyzed
6.5EPSS 0.002
CVE-2021-40109
A SSRF issue was discovered in Concrete CMS through 8.5.5. Users can access forbidden files on their local network. A user with permissions to upload files from external sites can upload a URL that redirects to an internal resource of any file type. The redirect is followed and loads the contents of the file from the redirected-to server. Files of disallowed types can be uploaded.
Published 2021-09-27 · Modified
6.4EPSS 0.005
CVE-2026-7887
For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status
Published 2026-05-21 · Analyzed
6.4EPSS 0.003
CVE-2026-7890
Concrete CMS 9.5.0 is vulnerable to SSRF via RSS Displayer Block
Published 2026-05-21 · Analyzed
6.4EPSS 0.002
CVE-2026-8236
Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate for endpoint /ccm/system/dialogs/file/usage/{fID}
Published 2026-05-21 · Analyzed
6.3EPSS 0.009
CVE-2026-8237
Concrete CMS 9.5.0 and below is vulnerable to IDOR in the`/ccm/frontend/conversations/message_detail` endpoint
Published 2026-05-21 · Analyzed
6.3EPSS 0.007
CVE-2022-43690
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 did not use strict comparison for the legacy_salt so that limited authentication bypass could occur if using this functionality. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.
Published 2022-11-14 · Modified
6.3EPSS 0.006
CVE-2026-8204
Concrete CMS 9.5.0 and below is vulnerable to Authorization Bypass in the Calendar Event Frontend Dialog
Published 2026-05-21 · Analyzed
6.3EPSS 0.004
← Prev2 / 5Next →