VendorsConcrete CMSconcrete_cmsany version
Vulnerabilities

Concrete CMS Concrete CMS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

179CVEs
CVE-2026-81921
In Concrete CMS 8.5.3 to 9,5,2, OAuth 2.0 Refresh-Token Grant Bypasses Account Status
Published 2026-09-15 · Analyzed
5.4EPSS 0.002
CVE-2026-81917
Concrete CMS below 9.5.3 is vulnerable to Stored XSS in the Document Library block file description and tags
Published 2026-09-11 · Analyzed
5.4EPSS 0.002
CVE-2026-81927
Concrete CMS before 9.5.3 is vulnerable to Stored XSS via SVG upload in "Reject" sanitization mode
Published 2026-09-15 · Analyzed
5.4EPSS 0.002
CVE-2017-18195
An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. An unauthenticated user can enumerate comments from all blog posts by POSTing requests to /index.php/tools/required/conversations/view_ajax with incremental 'cnvID' integers.
Published 2018-02-26 · Modified
5.31 PoCEPSS 0.111
CVE-2020-14961
Concrete5 before 8.5.3 does not constrain the sort direction to a valid asc or desc value.
Published 2020-06-21 · Modified
5.3EPSS 0.009
CVE-2021-22969
Concrete CMS (formerly concrete5) versions below 8.5.7 has a SSRF mitigation bypass using DNS Rebind attack giving an attacker the ability to fetch cloud IAAS (ex AWS) IAM keys.To fix this Concrete CMS no longer allows downloads from the local network and specifies the validated IP when downloading rather than relying on DNS.Discoverer: Adrian Tiron from FORTBRIDGE ( https://www.fortbridge.co.uk/ )The Concrete CMS team gave this a CVSS 3.1 score of 3.5 AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N . Please note that Cloud IAAS provider mis-configurations are not Concrete CMS vulnerabilities. A mitigation for this vulnerability is to make sure that the IMDS configurations are according to a cloud provider's best practices.This fix is also in Concrete version 9.0.0
Published 2021-11-19 · Modified
5.3EPSS 0.009
CVE-2023-28821
Concrete CMS (previously concrete5) before 9.1 did not have a rate limit for password resets.
Published 2023-04-28 · Modified
5.3EPSS 0.007
CVE-2022-43689
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XXE based DNS requests leading to IP disclosure.
Published 2022-11-14 · Modified
5.3EPSS 0.007
CVE-2023-28472
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 does not have Secure and HTTP only attributes set for ccmPoll cookies.
Published 2023-04-28 · Modified
5.3EPSS 0.006
CVE-2022-43691
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 inadvertently disclose server-side sensitive information (secrets in environment variables and server information) when Debug Mode is left on in production.
Published 2022-11-14 · Modified
5.3EPSS 0.005
CVE-2026-8327
Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass.
Published 2026-05-21 · Analyzed
5.3EPSS 0.003
CVE-2026-81915
In Concrete CMS below 9.5.3, Page Type update omits object-level authorization
Published 2026-09-11 · Analyzed
5.3EPSS 0.003
CVE-2026-68526
Concrete CMS before 9.5.3 is vulnerable to CSRF in the Calendar event duplicate dialog controller
Published 2026-09-11 · Analyzed
5.3EPSS 0.002
CVE-2024-8291
Concrete CMS Stored XSS in Image Editor Background Color
Published 2024-09-24 · Modified
5.1EPSS 0.005
CVE-2024-4350
Concrete CMS version 9 below 9.3.3 and below 8.5.18 are vulnerable to Stored XSS in RSS Displayer
Published 2024-08-09 · Modified
5.1EPSS 0.005
CVE-2026-81916
Incorrect Authorization in the Concrete CMS Express Entries Dashboard below version 9.5.3 Allows Entry Creation in an Unauthorized Object
Published 2026-09-11 · Analyzed
5.1EPSS 0.003
CVE-2026-68535
Concrete CMS 9.2.0 to 9.5.2 is vulnerable to Missing authorization in the Concrete CMS Area REST API block-create path letting an editor reference files outside their file-manager permissions
Published 2026-09-11 · Analyzed
5.1EPSS 0.002
CVE-2021-3111
The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.php/dashboard/express/entries/view/ URI.
Published 2021-01-08 · Modified
4.81 PoCEPSS 0.030
CVE-2024-1247
Concrete CMS version 9 before 9.2.5 vulnerable to stored XSS via the Role Name field
Published 2024-02-09 · Modified
4.8EPSS 0.012
CVE-2022-43695
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting (XSS) in dashboard/system/express/entities/associations because Concrete CMS allows association with an entity name that doesn’t exist or, if it does exist, contains XSS since it was not properly sanitized. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.
Published 2022-11-14 · Modified
4.8EPSS 0.006
CVE-2022-43688
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting (XSS) in icons since the Microsoft application tile color is not sanitized. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.
Published 2022-11-14 · Modified
4.8EPSS 0.006
CVE-2023-49337
Concrete CMS before 9.2.3 allows Stored XSS on the Admin Dashboard via /dashboard/system/basics/name. (8.5 and earlier are unaffected.)
Published 2023-12-25 · Analyzed
4.8EPSS 0.006
CVE-2023-48650
Concrete CMS before 8.5.14 and 9 before 9.2.3 is vulnerable to an admin adding a stored XSS payload via the Layout Preset name.
Published 2023-12-25 · Analyzed
4.8EPSS 0.005
CVE-2024-1246
Concrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import Feature
Published 2024-02-09 · Modified
4.8EPSS 0.005
CVE-2024-8661
Concrete CMS version 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" block
Published 2024-09-16 · Analyzed
4.8EPSS 0.004
CVE-2025-8573
Concrete CMS 9 through 9.4.2 is vulnerable to Stored XSS from Home Folder on Members Dashboard page
Published 2025-08-05 · Analyzed
4.81 PoCEPSS 0.004
CVE-2024-7394
Concrete CMS version 9.0.0 through 9.3.2 and below 8.5.18 - Stored XSS in getAttributeSetName()
Published 2024-08-08 · Modified
4.8EPSS 0.004
CVE-2024-1245
Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributes
Published 2024-02-09 · Modified
4.8EPSS 0.004
CVE-2024-7512
Concrete CMS Stored XSS in Board instances
Published 2024-08-09 · Modified
4.8EPSS 0.004
CVE-2024-2753
Concrete CMS version 9 below 9.2.8 and below 8.5.16 is vulnerable to stored XSS on the calendar color settings screen
Published 2024-04-03 · Analyzed
4.8EPSS 0.004
CVE-2024-3178
Concrete CMS versions 9 below 9.2.8 and versions below 8.5.16 are vulnerable to Cross-site Scripting (XSS) in the Advanced File Search Filter
Published 2024-04-03 · Analyzed
4.8EPSS 0.004
CVE-2024-3179
Concrete CMS version 9 before 9.2.8 and previous versions before 8.5.16 are vulnerable to Stored XSS in the Custom Class page
Published 2024-04-03 · Analyzed
4.8EPSS 0.004
CVE-2024-3180
Concrete CMS version 9 below 9.2.8 and previous versions below 8.5.16 is vulnerable to Stored XSS in blocks of type file
Published 2024-04-03 · Analyzed
4.8EPSS 0.004
CVE-2024-3181
Concrete CMS version 9 prior to 9.2.8 and previous versions prior to 8.5.16 are vulnerable to Stored XSS in the Search Field.
Published 2024-04-03 · Analyzed
4.8EPSS 0.004
CVE-2025-0660
Stored XSS in Folder Function by Rogue Admin
Published 2025-03-10 · Analyzed
4.8EPSS 0.003
CVE-2025-8571
Concrete CMS 9 through 9.4.2 and below 8.5.21 is vulnerable to Reflected Cross-Site Scripting (XSS) in Conversation Messages Dashboard Page
Published 2025-08-05 · Analyzed
4.8EPSS 0.003
CVE-2024-2179
Concrete CMS version 9 before 9.2.7 is vulnerable to Stored XSS via the Name field of a Group type
Published 2024-03-05 · Analyzed
4.8EPSS 0.003
CVE-2024-4353
Stored XSS in Generate Board Name Input Field
Published 2024-08-01 · Modified
4.8EPSS 0.003
CVE-2024-8660
Stored XSS in the "Top Navigator Bar" block
Published 2024-09-17 · Analyzed
4.8EPSS 0.003
CVE-2026-3244
Concrete CMS below version 9.4.8 is vulnerable to Stored XSS in Search Results via Page Names
Published 2026-03-04 · Analyzed
4.8EPSS 0.003
← Prev4 / 5Next →