Concretecms

Concrete Cms

231 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.33%
  • Veröffentlicht 14.09.2026 20:38:54
  • Zuletzt bearbeitet 18.09.2026 19:17:29

In Concrete CMS 9.2.0 through 9.5.2, the REST API page update endpoint (PUT /ccm/api/1.0/pages/{cID}) did not enforce page-property, page-template, or page-type authorization. A user granted only content-editing rights on a page could therefore alter...

  • EPSS 0.18%
  • Veröffentlicht 14.09.2026 20:34:23
  • Zuletzt bearbeitet 18.09.2026 19:13:05

Concrete CMS 9 through 9.5.2 did not validate a CSRF token in the orphaned block removal panel action (removeOrphanedBlocks). A remote attacker could craft a request that, when loaded by an authenticated user holding edit permission on the target pag...

  • EPSS 0.18%
  • Veröffentlicht 14.09.2026 20:14:25
  • Zuletzt bearbeitet 18.09.2026 19:12:09

Concrete CMS versions 9.0.0 to 9.5.2 stored the Page Container icon value submitted through the dashboard without validating it against the set of known container icons. The unvalidated value was later concatenated into the src attribute of an img ta...

  • EPSS 0.31%
  • Veröffentlicht 14.09.2026 19:54:11
  • Zuletzt bearbeitet 18.09.2026 19:23:08

Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page CSS via a DOM sink, permitting stored cross-site scripting. An editor-level user could execute script in an administrator's session...

  • EPSS 0.19%
  • Veröffentlicht 11.09.2026 20:21:48
  • Zuletzt bearbeitet 24.09.2026 20:02:32

Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function (POST /index.php/dashboard/system/express/entities/delete_entries) because the controller records but does not enforce a failed CS...

  • EPSS 0.3%
  • Veröffentlicht 11.09.2026 20:19:58
  • Zuletzt bearbeitet 18.09.2026 15:05:21

Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block. A user with edit_page_contents permissions could store a payload which executes in the browser of any visitor who viewed a page where ...

  • EPSS 0.28%
  • Veröffentlicht 11.09.2026 20:19:14
  • Zuletzt bearbeitet 18.09.2026 15:23:18

Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry submission against the entity of the posted form rather than the entity identified by the dashboard route. As a result, a user permitted to add entries to one Express ob...

  • EPSS 0.31%
  • Veröffentlicht 11.09.2026 20:16:06
  • Zuletzt bearbeitet 18.09.2026 15:18:54

Concrete CMS below 9.5.3 does not apply HTML output escaping to the file description and tags fields when rendering the Document Library block, so a user with permission to edit file properties could store a script payload that executed in the browse...

  • EPSS 0.28%
  • Veröffentlicht 11.09.2026 20:12:17
  • Zuletzt bearbeitet 24.09.2026 20:05:45

Concrete CMS Area API's block-create endpoint in versions 9.2.0 to 9.5.2 did not invoke the block type controller's validate() method on submitted data, which, for file-referencing blocks such as hero_image and gallery, is where the referenced file i...

  • EPSS 0.37%
  • Veröffentlicht 11.09.2026 19:39:03
  • Zuletzt bearbeitet 24.09.2026 20:07:18

Concrete CMS below 9.5.3 does not perform an object-level authorization check when a Page Type was updated. The Types::submit() dashboard controller loaded and saved the Page Type identified by a user-supplied ptID without calling canEditPageType(), ...