VendorsConcrete CMSconcrete_cmsall versions
Vulnerabilities

Concrete CMS Concrete CMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

196CVEs
CVE-2023-48649
Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows stored XSS on the Admin page via an uploaded file name.
Published 2023-11-17 · Modified
5.4EPSS 0.006
CVE-2023-44763
Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cross-Site Scripting (XSS). NOTE: the vendor's position is that a customer is supposed to know that "pdf" should be excluded from the allowed file types, even though pdf is one of the allowed file types in the default configuration.
Published 2023-10-10 · Modified
5.4EPSS 0.006
CVE-2023-44765
A Cross Site Scripting (XSS) vulnerability in Concrete CMS versions 8.5.12 and below, and 9.0 through 9.2.1 allows an attacker to execute arbitrary code via a crafted script to Plural Handle of the Data Objects from System & Settings.
Published 2023-10-06 · Modified
5.4EPSS 0.006
CVE-2023-28471
Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS via a container name.
Published 2023-04-28 · Modified
5.4EPSS 0.005
CVE-2023-28476
Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Tags on uploaded files.
Published 2023-04-28 · Modified
5.4EPSS 0.005
CVE-2023-44761
Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS versions affected to 8.5.13 and below, and 9.0.0 through 9.2.1 allow a local attacker to execute arbitrary code via a crafted script to the Forms of the Data objects.
Published 2023-10-06 · Modified
5.4EPSS 0.005
CVE-2021-40100
An issue was discovered in Concrete CMS through 8.5.5. Stored XSS can occur in Conversations when the Active Conversation Editor is set to Rich Text.
Published 2021-09-24 · Modified
5.4EPSS 0.005
CVE-2023-44764
A Cross Site Scripting (XSS) vulnerability in Concrete CMS before 9.2.3 exists via the Name parameter during installation (aka Site of Installation or Settings).
Published 2023-10-06 · Modified
5.4EPSS 0.005
CVE-2024-7398
Concrete CMS Stored XSS Vulnerability in Calendar Event Addition Feature
Published 2024-09-24 · Modified
5.4EPSS 0.005
CVE-2023-28820
Concrete CMS (previously concrete5) before 9.1 is vulnerable to stored XSS in RSS Displayer via the href attribute because the link element input was not sanitized.
Published 2023-04-28 · Modified
5.4EPSS 0.004
CVE-2026-8139
Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName
Published 2026-05-21 · Analyzed
5.4EPSS 0.003
CVE-2026-81921
In Concrete CMS 8.5.3 to 9,5,2, OAuth 2.0 Refresh-Token Grant Bypasses Account Status
Published 2026-09-15 · Analyzed
5.4EPSS 0.002
CVE-2026-81917
Concrete CMS below 9.5.3 is vulnerable to Stored XSS in the Document Library block file description and tags
Published 2026-09-11 · Analyzed
5.4EPSS 0.002
CVE-2026-81927
Concrete CMS before 9.5.3 is vulnerable to Stored XSS via SVG upload in "Reject" sanitization mode
Published 2026-09-15 · Analyzed
5.4EPSS 0.002
CVE-2017-18195
An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. An unauthenticated user can enumerate comments from all blog posts by POSTing requests to /index.php/tools/required/conversations/view_ajax with incremental 'cnvID' integers.
Published 2018-02-26 · Modified
5.31 PoCEPSS 0.111
CVE-2020-14961
Concrete5 before 8.5.3 does not constrain the sort direction to a valid asc or desc value.
Published 2020-06-21 · Modified
5.3EPSS 0.009
CVE-2021-22969
Concrete CMS (formerly concrete5) versions below 8.5.7 has a SSRF mitigation bypass using DNS Rebind attack giving an attacker the ability to fetch cloud IAAS (ex AWS) IAM keys.To fix this Concrete CMS no longer allows downloads from the local network and specifies the validated IP when downloading rather than relying on DNS.Discoverer: Adrian Tiron from FORTBRIDGE ( https://www.fortbridge.co.uk/ )The Concrete CMS team gave this a CVSS 3.1 score of 3.5 AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N . Please note that Cloud IAAS provider mis-configurations are not Concrete CMS vulnerabilities. A mitigation for this vulnerability is to make sure that the IMDS configurations are according to a cloud provider's best practices.This fix is also in Concrete version 9.0.0
Published 2021-11-19 · Modified
5.3EPSS 0.009
CVE-2023-28821
Concrete CMS (previously concrete5) before 9.1 did not have a rate limit for password resets.
Published 2023-04-28 · Modified
5.3EPSS 0.007
CVE-2022-43689
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XXE based DNS requests leading to IP disclosure.
Published 2022-11-14 · Modified
5.3EPSS 0.007
CVE-2023-28472
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 does not have Secure and HTTP only attributes set for ccmPoll cookies.
Published 2023-04-28 · Modified
5.3EPSS 0.006
CVE-2022-43691
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 inadvertently disclose server-side sensitive information (secrets in environment variables and server information) when Debug Mode is left on in production.
Published 2022-11-14 · Modified
5.3EPSS 0.005
CVE-2026-8327
Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass.
Published 2026-05-21 · Analyzed
5.3EPSS 0.003
CVE-2026-81915
In Concrete CMS below 9.5.3, Page Type update omits object-level authorization
Published 2026-09-11 · Analyzed
5.3EPSS 0.003
CVE-2026-68526
Concrete CMS before 9.5.3 is vulnerable to CSRF in the Calendar event duplicate dialog controller
Published 2026-09-11 · Analyzed
5.3EPSS 0.002
CVE-2024-8291
Concrete CMS Stored XSS in Image Editor Background Color
Published 2024-09-24 · Modified
5.1EPSS 0.005
CVE-2024-4350
Concrete CMS version 9 below 9.3.3 and below 8.5.18 are vulnerable to Stored XSS in RSS Displayer
Published 2024-08-09 · Modified
5.1EPSS 0.005
CVE-2026-81916
Incorrect Authorization in the Concrete CMS Express Entries Dashboard below version 9.5.3 Allows Entry Creation in an Unauthorized Object
Published 2026-09-11 · Analyzed
5.1EPSS 0.003
CVE-2026-68535
Concrete CMS 9.2.0 to 9.5.2 is vulnerable to Missing authorization in the Concrete CMS Area REST API block-create path letting an editor reference files outside their file-manager permissions
Published 2026-09-11 · Analyzed
5.1EPSS 0.002
CVE-2014-5107
concrete5 before 5.6.3 allows remote attackers to obtain the installation path via a direct request to (1) system/basics/editor.php, (2) system/view.php, (3) system/environment/file_storage_locations.php, (4) system/mail/importers.php, (5) system/mail/method.php, (6) system/permissions/file_types.php, (7) system/permissions/files.php, (8) system/permissions/tasks.php, (9) system/permissions/users.php, (10) system/seo/view.php, (11) view.php, (12) users/attributes.php, (13) scrapbook/view.php, (14) pages/attributes.php, (15) files/attributes.php, or (16) files/search.php in single_pages/dashboard/.
Published 2014-07-28 · Modified
5.0EPSS 0.030
CVE-2021-3111
The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.php/dashboard/express/entries/view/ URI.
Published 2021-01-08 · Modified
4.81 PoCEPSS 0.030
CVE-2024-1247
Concrete CMS version 9 before 9.2.5 vulnerable to stored XSS via the Role Name field
Published 2024-02-09 · Modified
4.8EPSS 0.012
CVE-2018-19146
Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTML data with a SCRIPT element.
Published 2019-06-17 · Modified
4.8EPSS 0.010
CVE-2022-43695
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting (XSS) in dashboard/system/express/entities/associations because Concrete CMS allows association with an entity name that doesn’t exist or, if it does exist, contains XSS since it was not properly sanitized. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.
Published 2022-11-14 · Modified
4.8EPSS 0.006
CVE-2023-44760
Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS v.9.2.1 allow an attacker to execute arbitrary code via a crafted script to the Header and Footer Tracking Codes of the SEO & Statistics. NOTE: the vendor disputes this because these header/footer changes can only be made by an admin, and allowing an admin to place JavaScript there is an intentional customization feature. Also, the exploitation method claimed by "sromanhu" does not provide any access to a Concrete CMS session, because the Concrete CMS session cookie is configured as HttpOnly.
Published 2023-10-23 · Modified
4.8EPSS 0.006
CVE-2022-43688
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting (XSS) in icons since the Microsoft application tile color is not sanitized. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.
Published 2022-11-14 · Modified
4.8EPSS 0.006
CVE-2023-44766
A Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 allows an attacker to execute arbitrary code via a crafted script to the SEO - Extra from Page Settings. NOTE: the vendor disputes this because this SEO-related header change can only be made by an admin, and allowing an admin to place JavaScript there is an intentional customization feature.
Published 2023-10-06 · Modified
4.8EPSS 0.006
CVE-2023-49337
Concrete CMS before 9.2.3 allows Stored XSS on the Admin Dashboard via /dashboard/system/basics/name. (8.5 and earlier are unaffected.)
Published 2023-12-25 · Analyzed
4.8EPSS 0.006
CVE-2023-48650
Concrete CMS before 8.5.14 and 9 before 9.2.3 is vulnerable to an admin adding a stored XSS payload via the Layout Preset name.
Published 2023-12-25 · Analyzed
4.8EPSS 0.005
CVE-2024-1246
Concrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import Feature
Published 2024-02-09 · Modified
4.8EPSS 0.005
CVE-2024-8661
Concrete CMS version 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" block
Published 2024-09-16 · Analyzed
4.8EPSS 0.004
← Prev4 / 5Next →