Concretecms

Concrete Cms

166 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 10.06.2026 06:59:03
  • Zuletzt bearbeitet 10.06.2026 20:11:16

Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the  in Permission, Cache, and Search components. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious serialized payload h...

  • EPSS 0.18%
  • Veröffentlicht 03.06.2026 18:10:10
  • Zuletzt bearbeitet 04.06.2026 15:20:18

Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. An unauthenticated attacker may trigger arbitrary PHP object instan...

  • EPSS 0.15%
  • Veröffentlicht 22.05.2026 14:18:06
  • Zuletzt bearbeitet 22.05.2026 14:18:06

Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inject arbitrary JavaScript that executes in the context of any authenticated user visiting the affected account pages. This can lead ...

  • EPSS 0.18%
  • Veröffentlicht 22.05.2026 14:06:34
  • Zuletzt bearbeitet 22.05.2026 14:06:34

Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog.  This can cause Cross-entity state tampering with view-only permission on one entry. To be affected, a website has to be using e...

  • EPSS 0.1%
  • Veröffentlicht 22.05.2026 13:58:55
  • Zuletzt bearbeitet 26.05.2026 14:55:32

Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edit_file_contents permission is CSRF'd into publishing an attacker-chosen previously-uploaded version (downgrade to an older version of a file, or activ...

  • EPSS 0.14%
  • Veröffentlicht 21.05.2026 22:16:50
  • Zuletzt bearbeitet 26.05.2026 18:32:36

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete.  The The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/...

  • EPSS 0.15%
  • Veröffentlicht 21.05.2026 22:16:49
  • Zuletzt bearbeitet 21.05.2026 22:16:49

In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation enabling redirect-to-internal bypasses.  The Concrete CMS security team gave this vulnerability a CVSS v.4....

  • EPSS 0.15%
  • Veröffentlicht 21.05.2026 22:16:49
  • Zuletzt bearbeitet 26.05.2026 17:41:14

Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updateCollectionAliasExternal bypasses being sanitized. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.0 with vector CVSS:4...

  • EPSS 0.14%
  • Veröffentlicht 21.05.2026 21:32:53
  • Zuletzt bearbeitet 26.05.2026 18:31:39

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete.  The The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/...

  • EPSS 0.13%
  • Veröffentlicht 21.05.2026 21:32:01
  • Zuletzt bearbeitet 26.05.2026 18:26:08

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/...