Concretecms

Concrete Cms

231 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Veröffentlicht 10.09.2026 23:16:31
  • Zuletzt bearbeitet 11.09.2026 15:17:05

Concrete CMS below 9.5.3 stores user validation hashes for multiple purposes (email/registration validation, password reset, and persistent login) in a single table with a type column, but the redemption path resolves a hash by value alone and does n...

  • EPSS 0.25%
  • Veröffentlicht 10.09.2026 23:10:55
  • Zuletzt bearbeitet 11.09.2026 15:17:00

Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the caller is permitted to view the calendar that owns ...

  • EPSS 0.15%
  • Veröffentlicht 10.09.2026 19:19:34
  • Zuletzt bearbeitet 10.09.2026 20:44:57

Concrete CMS 9 through 9.5.2 did not validate an anti-CSRF token in the Boards custom slot dialog controller (concrete/controllers/dialog/board/custom_slot.php) saveTemplate() action. The action created a board_slot_proxy Block and dispatched an Add...

  • EPSS 0.24%
  • Veröffentlicht 10.09.2026 18:21:06
  • Zuletzt bearbeitet 10.09.2026 19:58:20

Concrete CMS versions 8.3.0 through 9.5.2 are vulnerable to an authorization bypass in the Calendar event edit dialog (concrete/controllers/dialog/event/edit.php). The dialog checked permissions against the calendar identifier supplied in the request...

  • EPSS 0.25%
  • Veröffentlicht 08.09.2026 21:55:05
  • Zuletzt bearbeitet 10.09.2026 15:17:47

Concrete CMS below 9.5.3 registered view assets for every sub-block of a Stack, Container, or layout area without checking whether the requesting user could view that sub-block. An unauthenticated visitor could recover configuration values emitted by...

  • EPSS 0.14%
  • Veröffentlicht 10.06.2026 06:59:03
  • Zuletzt bearbeitet 23.07.2026 09:10:00

Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the  in Permission, Cache, and Search components. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious serialized payload h...

  • EPSS 0.18%
  • Veröffentlicht 03.06.2026 18:10:10
  • Zuletzt bearbeitet 11.09.2026 20:18:54

Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. The Form block and File/Set sinks were addressed in 9.5.2; the Work...

  • EPSS 0.15%
  • Veröffentlicht 22.05.2026 14:18:06
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inject arbitrary JavaScript that executes in the context of any authenticated user visiting the affected account pages. This can lead ...

  • EPSS 0.18%
  • Veröffentlicht 22.05.2026 14:06:34
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog.  This can cause Cross-entity state tampering with view-only permission on one entry. To be affected, a website has to be using e...

  • EPSS 0.1%
  • Veröffentlicht 22.05.2026 13:58:55
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edit_file_contents permission is CSRF'd into publishing an attacker-chosen previously-uploaded version (downgrade to an older version of a file, or activ...