Concretecms

Concrete Cms

231 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 16.09.2026 17:16:09
  • Zuletzt bearbeitet 21.09.2026 17:51:22

Concrete CMS before 9.5.3 exposed a legacy Express entry search endpoint that returned entry result JSON without invoking the canViewExpressEntries() permission check applied by the normal dashboard and CSV Export flow. An unauthenticated visitor who...

  • EPSS 0.21%
  • Veröffentlicht 16.09.2026 17:12:05
  • Zuletzt bearbeitet 21.09.2026 17:51:12

Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-check the state of the account the token had been issued to. The resource server's authorization validator confirmed only that a token existed,...

  • EPSS 0.32%
  • Veröffentlicht 16.09.2026 16:40:04
  • Zuletzt bearbeitet 21.09.2026 17:51:32

n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation endpoint (POST /ccm/api/1.0/users, the add() method of concrete/src/Api/Controller/Users.php) did not perform a permission check before creating an account. As a result, any valid OAuth t...

  • EPSS 0.27%
  • Veröffentlicht 16.09.2026 16:36:56
  • Zuletzt bearbeitet 21.09.2026 17:51:39

Concrete CMS 9 through 9.5.3 did not confirm that a board InstanceItem submitted to the custom-slot preview endpoint belonged to the board instance the requesting user was authorized to edit, and did not enforce page-view permission before generating...

  • EPSS 0.38%
  • Veröffentlicht 16.09.2026 16:33:53
  • Zuletzt bearbeitet 21.09.2026 17:51:55

Concrete CMS before 9.5.4 did not sanitize XML and XSLT documents uploaded through a public Form Block file-upload question. Plain XML uploads were validated by file extension only and stored as publicly accessible files that were served inline from ...

  • EPSS 0.43%
  • Veröffentlicht 16.09.2026 16:30:28
  • Zuletzt bearbeitet 21.09.2026 17:52:41

Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output encoding on the Dashboard user management page, where Date::getTimezoneDisplayName() returns any non-IANA value unchanged. A stored ...

  • EPSS 0.31%
  • Veröffentlicht 15.09.2026 20:21:03
  • Zuletzt bearbeitet 18.09.2026 15:15:46

Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling. When SVG processing was set to the non-default "Reject files containing potentially harmful elements" mode (concrete.file_manager.images.svg_sanitiz...

  • EPSS 0.37%
  • Veröffentlicht 15.09.2026 20:18:04
  • Zuletzt bearbeitet 21.09.2026 17:53:13

Concrete CMS before 9.5.3 improperly neutralized a user-supplied custom date format when rendering conversation messages, resulting in reflected cross-site scripting. An attacker could execute arbitrary JavaScript in the browser of a user who was tri...

  • EPSS 0.23%
  • Veröffentlicht 15.09.2026 20:16:12
  • Zuletzt bearbeitet 21.09.2026 17:53:06

Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level edit-permission check on the Express Form block's control-management actions, which relied solely on CSRF token validation. Because the token is bound to the user and action rather than t...

  • EPSS 0.31%
  • Veröffentlicht 15.09.2026 20:14:18
  • Zuletzt bearbeitet 21.09.2026 17:53:00

Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's duplicate-path confirmation dialog. The panel's check endpoint returned the submitted path unmodified in its JSON response, and client-...