Concretecms

Concrete Cms

166 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 21.05.2026 21:01:37
  • Zuletzt bearbeitet 26.05.2026 17:34:33

Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations/message_detail` endpoint returns the full content of any conversation message. An unauthenticated attacker can enumerate all conversation messages, including message...

  • EPSS 0.2%
  • Veröffentlicht 21.05.2026 21:00:52
  • Zuletzt bearbeitet 26.05.2026 17:25:49

Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/get_rating' endpoint confirms existence and returns rating score for any message by ID. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of ...

  • EPSS 0.2%
  • Veröffentlicht 21.05.2026 20:59:07
  • Zuletzt bearbeitet 26.05.2026 17:37:28

Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate. The endpoint /ccm/system/dialogs/file/usage/{fID} accepts an integer file ID in the URL and returns internal site structure data (page IDs, versions, URL ...

  • EPSS 0.21%
  • Veröffentlicht 21.05.2026 20:57:49
  • Zuletzt bearbeitet 26.05.2026 17:43:47

Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calendar Block since action_get_events does not check canView on the calendar which results in restricted event details being disclosed. The Concrete CMS security team gave thi...

  • EPSS 0.21%
  • Veröffentlicht 21.05.2026 20:56:33
  • Zuletzt bearbeitet 26.05.2026 14:58:25

Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend Dialog which can allow cross-calendar data disclosure. A public calendar block can be used as a pivot point to access private calendar data. The Concret...

  • EPSS 0.25%
  • Veröffentlicht 21.05.2026 20:55:21
  • Zuletzt bearbeitet 26.05.2026 14:59:02

Concrete CMS 9.5.0 and below  is vulnerable to unauthenticated file usage disclosure via missing permission check in the usage controller.  Any unauthenticated visitor can request /ccm/system/dialogs/file/usage/{fID} with any file ID and receive a li...

  • EPSS 0.12%
  • Veröffentlicht 21.05.2026 20:31:56
  • Zuletzt bearbeitet 26.05.2026 18:33:25

Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validate or sanitize $height. Any user with editor privileges can inject malicious JavaScript that executes in the context of any visitor's browser, potentia...

  • EPSS 0.18%
  • Veröffentlicht 21.05.2026 20:29:58
  • Zuletzt bearbeitet 26.05.2026 18:34:40

Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration name. The OAuth authorize template renders the integration name (admin-controlled) through Concrete's t() translation helper as a sprintf-style format. The <strong>...</st...

  • EPSS 0.3%
  • Veröffentlicht 21.05.2026 20:28:03
  • Zuletzt bearbeitet 26.05.2026 17:42:10

Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to privilege escalation to Administrative Group. Any authenticated user with access to the bulk user assignment dashboard page can add ...

  • EPSS 0.17%
  • Veröffentlicht 21.05.2026 20:25:11
  • Zuletzt bearbeitet 26.05.2026 14:57:19

Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/single_page/dashboard/extend/install.php.  An attacker who can cause an authenticated administrator to visit a crafted page,  and who h...