Concretecms

Concrete Cms

166 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 21.05.2026 21:20:13
  • Zuletzt bearbeitet 21.05.2026 22:16:49

For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status. A user with uIsActive=0 (suspended, banned, terminated employee) can still authenticate via OAuth and receive valid API tokens. The Concrete CMS security ...

  • EPSS 0.29%
  • Veröffentlicht 21.05.2026 21:18:39
  • Zuletzt bearbeitet 21.05.2026 22:16:49

Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter which can lead to file permission bypass. The `AddMessage` and `UpdateMessage` conversation controllers accept user-supplied file attachment ID...

  • EPSS 0.12%
  • Veröffentlicht 21.05.2026 21:17:22
  • Zuletzt bearbeitet 26.05.2026 14:56:43

Concrete CMS 9.5.0 and below is vulnerable to unauthorized file deletion due to an Inverted CSRF token check in the DeleteFile controller. The code throws an error when the token IS valid and proceeds with file deletion when the token is invalid or ...

  • EPSS 0.18%
  • Veröffentlicht 21.05.2026 21:15:31
  • Zuletzt bearbeitet 26.05.2026 17:18:10

Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass. The user-profile edit controller passes the entire raw POST array to UserInfo::update() without field whitelisting resulting in ...

  • EPSS 0.14%
  • Veröffentlicht 21.05.2026 21:14:18
  • Zuletzt bearbeitet 26.05.2026 17:19:42

Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection. Concrete\Core\Legacy\Pagination builds pagination links by raw-interpolating its $URL field into href="" (<a href="{$linkURL}" …>). Any aut...

  • EPSS 0.19%
  • Veröffentlicht 21.05.2026 21:13:07
  • Zuletzt bearbeitet 26.05.2026 17:13:07

Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in such a way that both public and private surveys are present on the site. An unauthenticated attacker can vote in the restricted sur...

  • EPSS 0.2%
  • Veröffentlicht 21.05.2026 21:11:58
  • Zuletzt bearbeitet 26.05.2026 17:24:12

Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure across every page with a configured summary template, revealing the existence of private, draft, and restricted pages while leaking title, path, description, and a...

  • EPSS 0.2%
  • Veröffentlicht 21.05.2026 21:09:18
  • Zuletzt bearbeitet 21.05.2026 22:16:48

Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail block via the exEntryID parameter. This IDOR leads to unauthorized access to all Express form submissions. The Concrete CMS security team g...

  • EPSS 0.22%
  • Veröffentlicht 21.05.2026 21:07:58
  • Zuletzt bearbeitet 21.05.2026 22:16:48

In Concrete CMS 9.5.0 and below,  the submit_password() method in concrete/controllers/single_page/download_file.php allows unauthorized file access since downloading permission-restricted files bypasses the view_file permission check. Files without ...

  • EPSS 0.2%
  • Veröffentlicht 21.05.2026 21:04:50
  • Zuletzt bearbeitet 26.05.2026 17:29:23

Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/message_page' endpoint returns the full content of any conversation message. An unauthenticated attacker can enumerate all conversation messages, including messages ...