Concretecms

Concrete Cms

231 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 11.09.2026 19:35:37
  • Zuletzt bearbeitet 25.09.2026 20:41:17

Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/controllers/dialog/event/duplicate.php) submit() action, which duplicated a calendar event after checking only canAccess() and t...

  • EPSS 0.52%
  • Veröffentlicht 11.09.2026 19:30:50
  • Zuletzt bearbeitet 24.09.2026 20:13:27

Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. An attacker can craft a single link on the site's own domain that sends a user to an arbitrary external site immediately after authentication, facilita...

  • EPSS 0.16%
  • Veröffentlicht 11.09.2026 19:27:49
  • Zuletzt bearbeitet 24.09.2026 20:18:47

Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature. The dashboard/users/groups/bulkupdate/confirm() endpoint moved the selected group tree nodes without validating an action token, so a state-cha...

  • EPSS 0.3%
  • Veröffentlicht 11.09.2026 19:24:05
  • Zuletzt bearbeitet 18.09.2026 19:00:06

Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot dialog. The custom_slot save_template endpoint authorizes the request only against the target board instance (canEditBoardContents()) and then persists the client-s...

  • EPSS 0.25%
  • Veröffentlicht 11.09.2026 18:20:25
  • Zuletzt bearbeitet 16.09.2026 17:40:45

Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values. Values submitted through the customizer (color channels and other style properties handled by ColorStyle and sibling...

  • EPSS 0.23%
  • Veröffentlicht 11.09.2026 17:49:47
  • Zuletzt bearbeitet 11.09.2026 18:22:06

Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the block alias route (Process::alias() in concrete/controllers/backend/block/process.php).It does not verify that the referenced block is genuinely orphaned on the target page, n...

  • EPSS 0.21%
  • Veröffentlicht 11.09.2026 17:34:55
  • Zuletzt bearbeitet 11.09.2026 20:17:22

Concrete CMS RSS Displayer block below version 9.5.3 rendered remote feed item titles without HTML escaping, resulting in stored cross-site scripting. An attacker able to control a title in a syndicated feed could execute script in the site origin f...

  • EPSS 0.21%
  • Veröffentlicht 11.09.2026 17:15:14
  • Zuletzt bearbeitet 11.09.2026 20:17:12

Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization; the Concrete CMS REST API's Express entry collection endpoint disabled the per-entry view permission check. An OAuth token with r...

  • EPSS 0.21%
  • Veröffentlicht 11.09.2026 17:09:46
  • Zuletzt bearbeitet 11.09.2026 20:19:13

Concrete CMS 9.2.0 to 9.5.2 contain a missing authorization vulnerability in the REST API Groups list endpoint. The listGroups() method in concrete/src/Api/Controller/Groups.php registers a permissions checker callback that unconditionally returns tr...

  • EPSS 0.34%
  • Veröffentlicht 10.09.2026 23:20:47
  • Zuletzt bearbeitet 11.09.2026 15:17:06

Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete authentication...