CVE-2026-8428
- EPSS 0.13%
- Veröffentlicht 21.05.2026 20:24:11
- Zuletzt bearbeitet 26.05.2026 14:57:02
Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update')) but the corresponding do_update() method in concrete/controllers/single_page/dashboard/system/update/update.php never calls $this->to...
CVE-2026-8426
- EPSS 0.17%
- Veröffentlicht 21.05.2026 20:22:09
- Zuletzt bearbeitet 26.05.2026 14:57:35
Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/prepare_remote_upgrade/<remoteMPID>. An attacker who controls the remote package returned for a known marketplace item ID can overwrite...
CVE-2026-8140
- EPSS 0.12%
- Veröffentlicht 21.05.2026 20:20:54
- Zuletzt bearbeitet 26.05.2026 18:43:21
Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/install/download/<remoteId>. The download() method in concrete/controllers/single_page/dashboard/extend/install.php checks only the canInstall...
CVE-2026-8417
- EPSS 0.12%
- Veröffentlicht 21.05.2026 20:19:42
- Zuletzt bearbeitet 26.05.2026 14:57:48
Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/do_update/<pkgHandle>. The do_update() method in concrete/controllers/single_page/dashboard/extend/update.php checks only canInstallPac...
CVE-2026-8135
- EPSS 0.47%
- Veröffentlicht 21.05.2026 20:16:39
- Zuletzt bearbeitet 26.05.2026 18:44:04
Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the ExpressEntryList block controller. An rogue administrator with privileges to add blocks to an area can bypass the intended protectio...
CVE-2026-8134
- EPSS 0.74%
- Veröffentlicht 21.05.2026 20:13:31
- Zuletzt bearbeitet 26.05.2026 19:02:40
Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue administrator with composer form editing rights can ...
CVE-2026-30662
- EPSS 0.29%
- Veröffentlicht 24.03.2026 00:00:00
- Zuletzt bearbeitet 24.03.2026 20:16:27
ConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. The 'download' method in 'concrete/controllers/backend/file.php' improperly manages memory when creating zip archives. It uses 'ZipArchive::addFromStri...
CVE-2026-2994
- EPSS 0.21%
- Veröffentlicht 04.03.2026 02:18:31
- Zuletzt bearbeitet 04.03.2026 21:35:06
Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configuration via group_id parameter which can leads to a security bypass since changes are saved prior to checking the CSRF token. The C...
CVE-2026-3240
- EPSS 0.21%
- Veröffentlicht 04.03.2026 02:15:53
- Zuletzt bearbeitet 04.03.2026 21:32:44
In Concrete CMS below version 9.4.8, a user with permission to edit a page with element Legacy form can perform a stored XSS attack towards high-privilege accounts via the Question field. The Concrete CMS security team gave this vulnerability a CVSS ...
CVE-2026-3241
- EPSS 0.21%
- Veröffentlicht 04.03.2026 02:12:51
- Zuletzt bearbeitet 04.03.2026 21:32:10
In Concrete CMS below version 9.4.8, a stored cross-site scripting (XSS) vulnerability exists in the "Legacy Form" block. An authenticated user with permissions to create or edit forms (e.g., a rogue administrator) can inject a persistent JavaScript ...