Concretecms

Concrete Cms

231 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 21.05.2026 22:16:50
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete.  The The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/...

  • EPSS 0.15%
  • Veröffentlicht 21.05.2026 22:16:49
  • Zuletzt bearbeitet 23.07.2026 16:10:00

In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation enabling redirect-to-internal bypasses.  The Concrete CMS security team gave this vulnerability a CVSS v.4....

  • EPSS 0.15%
  • Veröffentlicht 21.05.2026 22:16:49
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updateCollectionAliasExternal bypasses being sanitized. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.0 with vector CVSS:4...

  • EPSS 0.14%
  • Veröffentlicht 21.05.2026 21:32:53
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete.  The The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/...

  • EPSS 0.13%
  • Veröffentlicht 21.05.2026 21:32:01
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/...

  • EPSS 0.13%
  • Veröffentlicht 21.05.2026 21:31:21
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/...

  • EPSS 0.13%
  • Veröffentlicht 21.05.2026 21:30:28
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/...

  • EPSS 0.13%
  • Veröffentlicht 21.05.2026 21:29:50
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/U...

  • EPSS 0.13%
  • Veröffentlicht 21.05.2026 21:29:13
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L...

  • EPSS 0.13%
  • Veröffentlicht 21.05.2026 21:28:32
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:...