CVE-2026-8409
- EPSS 0.14%
- Veröffentlicht 21.05.2026 22:16:50
- Zuletzt bearbeitet 23.07.2026 16:10:00
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete. The The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/...
CVE-2026-7890
- EPSS 0.15%
- Veröffentlicht 21.05.2026 22:16:49
- Zuletzt bearbeitet 23.07.2026 16:10:00
In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation enabling redirect-to-internal bypasses. The Concrete CMS security team gave this vulnerability a CVSS v.4....
CVE-2026-8139
- EPSS 0.15%
- Veröffentlicht 21.05.2026 22:16:49
- Zuletzt bearbeitet 23.07.2026 16:10:00
Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updateCollectionAliasExternal bypasses being sanitized. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.0 with vector CVSS:4...
CVE-2026-8410
- EPSS 0.14%
- Veröffentlicht 21.05.2026 21:32:53
- Zuletzt bearbeitet 23.07.2026 16:10:00
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete. The The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/...
CVE-2026-8411
- EPSS 0.13%
- Veröffentlicht 21.05.2026 21:32:01
- Zuletzt bearbeitet 23.07.2026 16:10:00
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/...
CVE-2026-8412
- EPSS 0.13%
- Veröffentlicht 21.05.2026 21:31:21
- Zuletzt bearbeitet 23.07.2026 16:10:00
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/...
CVE-2026-8413
- EPSS 0.13%
- Veröffentlicht 21.05.2026 21:30:28
- Zuletzt bearbeitet 23.07.2026 16:10:00
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/...
CVE-2026-8414
- EPSS 0.13%
- Veröffentlicht 21.05.2026 21:29:50
- Zuletzt bearbeitet 23.07.2026 16:10:00
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/U...
CVE-2026-8415
- EPSS 0.13%
- Veröffentlicht 21.05.2026 21:29:13
- Zuletzt bearbeitet 23.07.2026 16:10:00
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L...
CVE-2026-8416
- EPSS 0.13%
- Veröffentlicht 21.05.2026 21:28:32
- Zuletzt bearbeitet 23.07.2026 16:10:00
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:...