CVE-2026-8427
- EPSS 0.13%
- Veröffentlicht 21.05.2026 21:27:03
- Zuletzt bearbeitet 23.07.2026 16:10:00
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/...
CVE-2026-8432
- EPSS 0.13%
- Veröffentlicht 21.05.2026 21:26:17
- Zuletzt bearbeitet 23.07.2026 16:10:00
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P...
CVE-2026-8433
- EPSS 0.13%
- Veröffentlicht 21.05.2026 21:25:17
- Zuletzt bearbeitet 23.07.2026 16:10:00
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI...
CVE-2026-8434
- EPSS 0.13%
- Veröffentlicht 21.05.2026 21:23:52
- Zuletzt bearbeitet 23.07.2026 16:10:00
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P...
CVE-2026-8435
- EPSS 0.12%
- Veröffentlicht 21.05.2026 21:22:30
- Zuletzt bearbeitet 23.07.2026 16:10:00
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P...
CVE-2026-7887
- EPSS 0.17%
- Veröffentlicht 21.05.2026 21:20:13
- Zuletzt bearbeitet 23.07.2026 16:10:00
For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status. A user with uIsActive=0 (suspended, banned, terminated employee) can still authenticate via OAuth and receive valid API tokens. The Concrete CMS security ...
CVE-2026-7886
- EPSS 0.29%
- Veröffentlicht 21.05.2026 21:18:39
- Zuletzt bearbeitet 23.07.2026 11:10:00
Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter which can lead to file permission bypass. The `AddMessage` and `UpdateMessage` conversation controllers accept user-supplied file attachment ID...
CVE-2026-7882
- EPSS 0.12%
- Veröffentlicht 21.05.2026 21:17:22
- Zuletzt bearbeitet 23.07.2026 16:10:00
Concrete CMS 9.5.0 and below is vulnerable to unauthorized file deletion due to an Inverted CSRF token check in the DeleteFile controller. The code throws an error when the token IS valid and proceeds with file deletion when the token is invalid or ...
CVE-2026-8327
- EPSS 0.18%
- Veröffentlicht 21.05.2026 21:15:31
- Zuletzt bearbeitet 23.07.2026 16:10:00
Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass. The user-profile edit controller passes the entire raw POST array to UserInfo::update() without field whitelisting resulting in ...
CVE-2026-8245
- EPSS 0.14%
- Veröffentlicht 21.05.2026 21:14:18
- Zuletzt bearbeitet 23.07.2026 11:10:00
Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection. Concrete\Core\Legacy\Pagination builds pagination links by raw-interpolating its $URL field into href="" (<a href="{$linkURL}" …>). Any aut...