CVE-2026-8237
- EPSS 0.2%
- Veröffentlicht 21.05.2026 21:01:37
- Zuletzt bearbeitet 26.05.2026 17:34:33
Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations/message_detail` endpoint returns the full content of any conversation message. An unauthenticated attacker can enumerate all conversation messages, including message...
CVE-2026-8239
- EPSS 0.2%
- Veröffentlicht 21.05.2026 21:00:52
- Zuletzt bearbeitet 26.05.2026 17:25:49
Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/get_rating' endpoint confirms existence and returns rating score for any message by ID. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of ...
CVE-2026-8236
- EPSS 0.2%
- Veröffentlicht 21.05.2026 20:59:07
- Zuletzt bearbeitet 26.05.2026 17:37:28
Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate. The endpoint /ccm/system/dialogs/file/usage/{fID} accepts an integer file ID in the URL and returns internal site structure data (page IDs, versions, URL ...
CVE-2026-8205
- EPSS 0.21%
- Veröffentlicht 21.05.2026 20:57:49
- Zuletzt bearbeitet 26.05.2026 17:43:47
Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calendar Block since action_get_events does not check canView on the calendar which results in restricted event details being disclosed. The Concrete CMS security team gave thi...
CVE-2026-8204
- EPSS 0.21%
- Veröffentlicht 21.05.2026 20:56:33
- Zuletzt bearbeitet 26.05.2026 14:58:25
Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend Dialog which can allow cross-calendar data disclosure. A public calendar block can be used as a pivot point to access private calendar data. The Concret...
CVE-2026-6826
- EPSS 0.25%
- Veröffentlicht 21.05.2026 20:55:21
- Zuletzt bearbeitet 26.05.2026 14:59:02
Concrete CMS 9.5.0 and below is vulnerable to unauthenticated file usage disclosure via missing permission check in the usage controller. Any unauthenticated visitor can request /ccm/system/dialogs/file/usage/{fID} with any file ID and receive a li...
CVE-2026-8203
- EPSS 0.12%
- Veröffentlicht 21.05.2026 20:31:56
- Zuletzt bearbeitet 26.05.2026 18:33:25
Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validate or sanitize $height. Any user with editor privileges can inject malicious JavaScript that executes in the context of any visitor's browser, potentia...
CVE-2026-8197
- EPSS 0.18%
- Veröffentlicht 21.05.2026 20:29:58
- Zuletzt bearbeitet 26.05.2026 18:34:40
Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration name. The OAuth authorize template renders the integration name (admin-controlled) through Concrete's t() translation helper as a sprintf-style format. The <strong>...</st...
CVE-2026-8350
- EPSS 0.3%
- Veröffentlicht 21.05.2026 20:28:03
- Zuletzt bearbeitet 26.05.2026 17:42:10
Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to privilege escalation to Administrative Group. Any authenticated user with access to the bulk user assignment dashboard page can add ...
CVE-2026-8421
- EPSS 0.17%
- Veröffentlicht 21.05.2026 20:25:11
- Zuletzt bearbeitet 26.05.2026 14:57:19
Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/single_page/dashboard/extend/install.php. An attacker who can cause an authenticated administrator to visit a crafted page, and who h...