Concretecms

Concrete Cms

231 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 15.09.2026 19:52:04
  • Zuletzt bearbeitet 21.09.2026 17:51:00

Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap reorder action (Concrete\Controller\Backend\Dashboard\SitemapUpdate) using only the global access_sitemap task permission and did not check per-page edit permission before updating each pag...

  • EPSS 0.29%
  • Veröffentlicht 15.09.2026 19:49:48
  • Zuletzt bearbeitet 21.09.2026 17:50:50

Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side Request Forgery iremote file import via cross-port reuse of a host's validated DNS pin. When multiple remote URLs share the same host, only the first `ValidatedRemoteUrl` is retained and reused...

  • EPSS 0.28%
  • Veröffentlicht 15.09.2026 19:30:13
  • Zuletzt bearbeitet 21.09.2026 17:50:42

Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs . An authenticated user holding only view permission on a single Express entity could therefore perm...

  • EPSS 0.37%
  • Veröffentlicht 15.09.2026 19:27:59
  • Zuletzt bearbeitet 21.09.2026 17:50:08

Concrete CMS before 9.5.3 did not enforce a destination-side authorization check and did not validate a CSRF token in the multilingual page assignment backend action (Backend\Page\Multilingual::assign). As a result, an authenticated user who held the...

  • EPSS 0.24%
  • Veröffentlicht 15.09.2026 19:17:36
  • Zuletzt bearbeitet 16.09.2026 19:16:15

Concrete CMS 9.0.0 through 9.5.2 was missing an authorization check on the Express entries advanced-search dashboard action. The advanced_search() method in DashboardSelectableExpressEntryListTrait resolved an Express entity directly from a user-supp...

  • EPSS 0.25%
  • Veröffentlicht 15.09.2026 19:17:36
  • Zuletzt bearbeitet 16.09.2026 19:16:15

Concrete CMS 9 through 9.5.2 did not perform an authorization check on several board-instance actions in the Boards area of the Dashboard. The instance details single-page controller resolved a board instance directly from an attacker-supplied instan...

  • EPSS 0.25%
  • Veröffentlicht 15.09.2026 19:17:36
  • Zuletzt bearbeitet 16.09.2026 19:16:15

Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard characters in the keyword search filters used by the file manager, file folders, and page list, allowing an authenticated user with editor-level or higher privileges to submit a crafted sea...

  • EPSS 0.24%
  • Veröffentlicht 15.09.2026 19:17:17
  • Zuletzt bearbeitet 16.09.2026 19:16:15

Concrete CMS 9 through 9.5.2 does not perform an authorization check in three actions of the Boards data source dashboard controller (update, update_data_source, and delete_data_source), which resolve a ConfiguredDataSource directly from an attacker-...

  • EPSS 0.18%
  • Veröffentlicht 15.09.2026 18:55:57
  • Zuletzt bearbeitet 21.09.2026 17:50:00

Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in the theme page-template activation feature. The Dashboard theme Inspect controller's activate_files() action created PageTemplate records from attacker-supplied pageTempl...

  • EPSS 0.23%
  • Veröffentlicht 15.09.2026 18:53:26
  • Zuletzt bearbeitet 18.09.2026 15:28:11

In Concrete CMS before 9.5.3, the SEO Bulk Update Meta Tags editor did not check per-page edit permissions before saving. The saveRecord() action validated the per-page CSRF token but never called canEditPageProperties() for the target page, so a use...