VendorsConcrete CMSconcrete_cmsany version
Vulnerabilities

Concrete CMS Concrete CMS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

179CVEs
CVE-2026-3242
Concrete CMS below 9.4.8 is vulnerable to Stored XSS in the Switch Language block
Published 2026-03-04 · Analyzed
4.8EPSS 0.003
CVE-2026-3241
Concrete CMS below version 9.4.8 is vulnerable to a stored cross-site scripting (XSS) in the "Legacy Form" block.
Published 2026-03-04 · Analyzed
4.8EPSS 0.003
CVE-2026-3240
Concrete CMS below 9.4.8 is vulnerable to Stored XSS via Legacy form
Published 2026-03-04 · Analyzed
4.8EPSS 0.003
CVE-2026-81918
Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block
Published 2026-09-11 · Analyzed
4.8EPSS 0.003
CVE-2026-8353
Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in atomik theme
Published 2026-05-22 · Analyzed
4.8EPSS 0.003
CVE-2026-7886
Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter
Published 2026-05-21 · Analyzed
4.3EPSS 0.005
CVE-2026-8347
Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialog
Published 2026-05-22 · Analyzed
4.3EPSS 0.003
CVE-2023-48651
Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) at /ccm/system/dialogs/file/delete/1/submit.
Published 2023-12-25 · Analyzed
4.3EPSS 0.003
CVE-2023-48653
Concrete CMS before 8.5.14 and 9 before 9.2.3 allows Cross Site Request Forgery (CSRF) via ccm/calendar/dialogs/event/delete/submit. An attacker can force an admin to delete events on the site because the event ID is numeric and sequential.
Published 2023-12-25 · Analyzed
4.3EPSS 0.003
CVE-2023-48652
Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) via /ccm/system/dialogs/logs/delete_all/submit. An attacker can force an admin user to delete server report logs on a web application to which they are currently authenticated.
Published 2023-12-25 · Modified
4.3EPSS 0.002
CVE-2026-81920
Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Dashboard SEO Excluded Words Reset Endpoint
Published 2026-09-15 · Analyzed
4.3EPSS 0.002
CVE-2026-7882
Concrete CMS 9.5.0 and below is vulnerable to CSRF via the DeleteFile controller
Published 2026-05-21 · Analyzed
4.3EPSS 0.002
CVE-2026-8340
Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion
Published 2026-05-22 · Analyzed
4.3EPSS 0.001
CVE-2026-81919
Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Block Arrangement Endpoint
Published 2026-09-15 · Analyzed
4.3EPSS 0.001
CVE-2023-28473
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to possible Auth bypass in the jobs section.
Published 2023-04-28 · Modified
3.3EPSS 0.008
CVE-2026-87031
Missing authorization in the REST API user creation endpoint in Concrete CMS 9.2.0 through 9.5.3 allows arbitrary account creation
Published 2026-09-16 · Analyzed
2.7EPSS 0.003
CVE-2026-81923
Concrete CMS below 9.5.3 is missing authorization in the SEO Bulk Update Meta Tags editor
Published 2026-09-15 · Analyzed
2.7EPSS 0.003
CVE-2026-81922
"In Concrete CMS below 9.5.3, there is Missing authorization in the sitemap page reorder allowing low-privilege users to reorder arbitrary pages "
Published 2026-09-15 · Analyzed
2.7EPSS 0.003
CVE-2026-18425
IDOR in Concrete CMS 9.0.0 through 9.5.2 dashboard sitemap reorder (SitemapUpdate::updateDisplayOrder) allows an authenticated sitemap user to reorder arbitrary pages
Published 2026-09-15 · Analyzed
2.7EPSS 0.001
← Prev5 / 5