Concretecms

Concrete Cms

166 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Veröffentlicht 21.05.2026 21:31:21
  • Zuletzt bearbeitet 26.05.2026 18:25:09

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/...

  • EPSS 0.13%
  • Veröffentlicht 21.05.2026 21:30:28
  • Zuletzt bearbeitet 26.05.2026 19:01:42

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/...

  • EPSS 0.13%
  • Veröffentlicht 21.05.2026 21:29:50
  • Zuletzt bearbeitet 26.05.2026 18:59:58

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/U...

  • EPSS 0.13%
  • Veröffentlicht 21.05.2026 21:29:13
  • Zuletzt bearbeitet 26.05.2026 18:58:27

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L...

  • EPSS 0.13%
  • Veröffentlicht 21.05.2026 21:28:32
  • Zuletzt bearbeitet 26.05.2026 18:55:36

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:...

  • EPSS 0.13%
  • Veröffentlicht 21.05.2026 21:27:03
  • Zuletzt bearbeitet 26.05.2026 18:49:19

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/...

  • EPSS 0.13%
  • Veröffentlicht 21.05.2026 21:26:17
  • Zuletzt bearbeitet 26.05.2026 18:46:09

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P...

  • EPSS 0.13%
  • Veröffentlicht 21.05.2026 21:25:17
  • Zuletzt bearbeitet 26.05.2026 18:19:12

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI...

  • EPSS 0.13%
  • Veröffentlicht 21.05.2026 21:23:52
  • Zuletzt bearbeitet 26.05.2026 17:59:46

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P...

  • EPSS 0.12%
  • Veröffentlicht 21.05.2026 21:22:30
  • Zuletzt bearbeitet 21.05.2026 22:16:52

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P...