Concretecms

Concrete Cms

231 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 21.05.2026 21:13:07
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in such a way that both public and private surveys are present on the site. An unauthenticated attacker can vote in the restricted sur...

  • EPSS 0.2%
  • Veröffentlicht 21.05.2026 21:11:58
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure across every page with a configured summary template, revealing the existence of private, draft, and restricted pages while leaking title, path, description, and a...

  • EPSS 0.21%
  • Veröffentlicht 21.05.2026 21:09:18
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail block via the exEntryID parameter. This IDOR leads to unauthorized access to all Express form submissions. The Concrete CMS security team g...

  • EPSS 0.22%
  • Veröffentlicht 21.05.2026 21:07:58
  • Zuletzt bearbeitet 23.07.2026 16:10:00

In Concrete CMS 9.5.0 and below,  the submit_password() method in concrete/controllers/single_page/download_file.php allows unauthorized file access since downloading permission-restricted files bypasses the view_file permission check. Files without ...

  • EPSS 0.2%
  • Veröffentlicht 21.05.2026 21:04:50
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/message_page' endpoint returns the full content of any conversation message. An unauthenticated attacker can enumerate all conversation messages, including messages ...

  • EPSS 0.46%
  • Veröffentlicht 21.05.2026 21:01:37
  • Zuletzt bearbeitet 23.07.2026 11:10:00

Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations/message_detail` endpoint returns the full content of any conversation message. An unauthenticated attacker can enumerate all conversation messages, including message...

  • EPSS 0.2%
  • Veröffentlicht 21.05.2026 21:00:52
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/get_rating' endpoint confirms existence and returns rating score for any message by ID. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of ...

  • EPSS 0.2%
  • Veröffentlicht 21.05.2026 20:59:07
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate. The endpoint /ccm/system/dialogs/file/usage/{fID} accepts an integer file ID in the URL and returns internal site structure data (page IDs, versions, URL ...

  • EPSS 0.21%
  • Veröffentlicht 21.05.2026 20:57:49
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calendar Block since action_get_events does not check canView on the calendar which results in restricted event details being disclosed. The Concrete CMS security team gave thi...

  • EPSS 0.21%
  • Veröffentlicht 21.05.2026 20:56:33
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend Dialog which can allow cross-calendar data disclosure. A public calendar block can be used as a pivot point to access private calendar data. The Concret...