VendorsConcrete CMSconcrete_cmsall versions
Vulnerabilities

Concrete CMS Concrete CMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

196CVEs
CVE-2025-8573
Concrete CMS 9 through 9.4.2 is vulnerable to Stored XSS from Home Folder on Members Dashboard page
Published 2025-08-05 · Analyzed
4.81 PoCEPSS 0.004
CVE-2024-7394
Concrete CMS version 9.0.0 through 9.3.2 and below 8.5.18 - Stored XSS in getAttributeSetName()
Published 2024-08-08 · Modified
4.8EPSS 0.004
CVE-2024-1245
Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributes
Published 2024-02-09 · Modified
4.8EPSS 0.004
CVE-2024-7512
Concrete CMS Stored XSS in Board instances
Published 2024-08-09 · Modified
4.8EPSS 0.004
CVE-2024-2753
Concrete CMS version 9 below 9.2.8 and below 8.5.16 is vulnerable to stored XSS on the calendar color settings screen
Published 2024-04-03 · Analyzed
4.8EPSS 0.004
CVE-2024-3178
Concrete CMS versions 9 below 9.2.8 and versions below 8.5.16 are vulnerable to Cross-site Scripting (XSS) in the Advanced File Search Filter
Published 2024-04-03 · Analyzed
4.8EPSS 0.004
CVE-2024-3179
Concrete CMS version 9 before 9.2.8 and previous versions before 8.5.16 are vulnerable to Stored XSS in the Custom Class page
Published 2024-04-03 · Analyzed
4.8EPSS 0.004
CVE-2024-3180
Concrete CMS version 9 below 9.2.8 and previous versions below 8.5.16 is vulnerable to Stored XSS in blocks of type file
Published 2024-04-03 · Analyzed
4.8EPSS 0.004
CVE-2024-3181
Concrete CMS version 9 prior to 9.2.8 and previous versions prior to 8.5.16 are vulnerable to Stored XSS in the Search Field.
Published 2024-04-03 · Analyzed
4.8EPSS 0.004
CVE-2025-0660
Stored XSS in Folder Function by Rogue Admin
Published 2025-03-10 · Analyzed
4.8EPSS 0.003
CVE-2025-8571
Concrete CMS 9 through 9.4.2 and below 8.5.21 is vulnerable to Reflected Cross-Site Scripting (XSS) in Conversation Messages Dashboard Page
Published 2025-08-05 · Analyzed
4.8EPSS 0.003
CVE-2024-2179
Concrete CMS version 9 before 9.2.7 is vulnerable to Stored XSS via the Name field of a Group type
Published 2024-03-05 · Analyzed
4.8EPSS 0.003
CVE-2024-4353
Stored XSS in Generate Board Name Input Field
Published 2024-08-01 · Modified
4.8EPSS 0.003
CVE-2024-8660
Stored XSS in the "Top Navigator Bar" block
Published 2024-09-17 · Analyzed
4.8EPSS 0.003
CVE-2026-3242
Concrete CMS below 9.4.8 is vulnerable to Stored XSS in the Switch Language block
Published 2026-03-04 · Analyzed
4.8EPSS 0.003
CVE-2026-3244
Concrete CMS below version 9.4.8 is vulnerable to Stored XSS in Search Results via Page Names
Published 2026-03-04 · Analyzed
4.8EPSS 0.003
CVE-2026-3241
Concrete CMS below version 9.4.8 is vulnerable to a stored cross-site scripting (XSS) in the "Legacy Form" block.
Published 2026-03-04 · Analyzed
4.8EPSS 0.003
CVE-2026-3240
Concrete CMS below 9.4.8 is vulnerable to Stored XSS via Legacy form
Published 2026-03-04 · Analyzed
4.8EPSS 0.003
CVE-2026-81918
Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block
Published 2026-09-11 · Analyzed
4.8EPSS 0.003
CVE-2026-8353
Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in atomik theme
Published 2026-05-22 · Analyzed
4.8EPSS 0.003
CVE-2014-5108
Cross-site scripting (XSS) vulnerability in single_pages\download_file.php in concrete5 before 5.6.3 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to index.php/download_file.
Published 2014-07-28 · Modified
4.3EPSS 0.023
CVE-2014-9526
Multiple cross-site scripting (XSS) vulnerabilities in concrete5 5.7.2.1, 5.7.2, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gName parameter in single_pages/dashboard/users/groups/bulkupdate.php or (2) instance_id parameter in tools/dashboard/sitemap_drag_request.php.
Published 2015-01-05 · Modified
4.3EPSS 0.019
CVE-2026-7886
Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter
Published 2026-05-21 · Analyzed
4.3EPSS 0.005
CVE-2026-8347
Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialog
Published 2026-05-22 · Analyzed
4.3EPSS 0.003
CVE-2023-48651
Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) at /ccm/system/dialogs/file/delete/1/submit.
Published 2023-12-25 · Analyzed
4.3EPSS 0.003
CVE-2023-48653
Concrete CMS before 8.5.14 and 9 before 9.2.3 allows Cross Site Request Forgery (CSRF) via ccm/calendar/dialogs/event/delete/submit. An attacker can force an admin to delete events on the site because the event ID is numeric and sequential.
Published 2023-12-25 · Analyzed
4.3EPSS 0.003
CVE-2023-48652
Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) via /ccm/system/dialogs/logs/delete_all/submit. An attacker can force an admin user to delete server report logs on a web application to which they are currently authenticated.
Published 2023-12-25 · Modified
4.3EPSS 0.002
CVE-2026-81920
Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Dashboard SEO Excluded Words Reset Endpoint
Published 2026-09-15 · Analyzed
4.3EPSS 0.002
CVE-2026-7882
Concrete CMS 9.5.0 and below is vulnerable to CSRF via the DeleteFile controller
Published 2026-05-21 · Analyzed
4.3EPSS 0.002
CVE-2026-8340
Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion
Published 2026-05-22 · Analyzed
4.3EPSS 0.001
CVE-2026-81919
Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Block Arrangement Endpoint
Published 2026-09-15 · Analyzed
4.3EPSS 0.001
CVE-2023-28473
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to possible Auth bypass in the jobs section.
Published 2023-04-28 · Modified
3.3EPSS 0.008
CVE-2026-87031
Missing authorization in the REST API user creation endpoint in Concrete CMS 9.2.0 through 9.5.3 allows arbitrary account creation
Published 2026-09-16 · Analyzed
2.7EPSS 0.003
CVE-2026-81922
"In Concrete CMS below 9.5.3, there is Missing authorization in the sitemap page reorder allowing low-privilege users to reorder arbitrary pages "
Published 2026-09-15 · Analyzed
2.7EPSS 0.003
CVE-2026-81923
Concrete CMS below 9.5.3 is missing authorization in the SEO Bulk Update Meta Tags editor
Published 2026-09-15 · Analyzed
2.7EPSS 0.003
CVE-2026-18425
IDOR in Concrete CMS 9.0.0 through 9.5.2 dashboard sitemap reorder (SitemapUpdate::updateDisplayOrder) allows an authenticated sitemap user to reorder arbitrary pages
Published 2026-09-15 · Analyzed
2.7EPSS 0.001
← Prev5 / 5