Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Concrete CMS — Vulnerabilities & Security Advisories 72

All 72 CVE vulnerabilities found in Concrete CMS, with AI-generated Chinese analysis, references, and POCs.

This page details security vulnerabilities, weaknesses, and associated tags for the Concrete CMS product. It aggregates data related to common flaw types found within this content management system, providing a centralized view of known security issues. The content includes a comprehensive collection of reported vulnerabilities affecting Concrete CMS, covering incidents identified from the system's inception through the most recent updates. By reviewing this aggregated data, users can effectively track vendor advisories to stay informed about critical patches and security notices. Readers can also use this resource to understand specific weakness classes that impact the platform, allowing for better risk assessment and mitigation strategies. Furthermore, the page serves as a historical record, enabling users to look up a product's vulnerability history over time. This continuity helps in identifying patterns, assessing the long-term security posture of Concrete CMS, and understanding how previous issues have been addressed. The information presented is strictly technical and factual, designed to assist security professionals, developers, and administrators in maintaining the integrity and safety of their deployments. There is no promotional content or marketing language included in this summary. The focus remains entirely on the technical aspects of vulnerability management and the specific security challenges associated with Concrete CMS.

Vendor: Concrete CMS

CVE IDTitleCVSSSeverityPublished
CVE-2026-10721 Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and Search components CWE-502--2026-06-10
CVE-2026-7888 Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. CWE-502--2026-06-03
CVE-2026-8353 Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in atomik theme CWE-79--2026-05-22
CVE-2026-8347 Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialog CWE-639--2026-05-22
CVE-2026-8340 Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion CWE-352--2026-05-22
CVE-2026-8139 Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName CWE-79--2026-05-21
CVE-2026-7890 Concrete CMS 9.5.0 is vulnerable to SSRF via RSS Displayer Block CWE-918--2026-05-21
CVE-2026-8409 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete CWE-352--2026-05-21
CVE-2026-8410 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete CWE-352--2026-05-21
CVE-2026-8411 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete CWE-352--2026-05-21
CVE-2026-8412 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache CWE-352--2026-05-21
CVE-2026-8413 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design CWE-352--2026-05-21
CVE-2026-8414 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate CWE-352--2026-05-21
CVE-2026-8415 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder CWE-352--2026-05-21
CVE-2026-8416 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id) CWE-352--2026-05-21
CVE-2026-8427 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id) CWE-352--2026-05-21
CVE-2026-8432 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star() CWE-352--2026-05-21
CVE-2026-8433 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan() CWE-352--2026-05-21
CVE-2026-8434 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple() CWE-352--2026-05-21
CVE-2026-8435 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion() CWE-352--2026-05-21
CVE-2026-7887 For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status CWE-1287--2026-05-21
CVE-2026-7886 Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter CWE-639--2026-05-21
CVE-2026-7882 Concrete CMS 9.5.0 and below is vulnerable to CSRF via the DeleteFile controller CWE-352--2026-05-21
CVE-2026-8327 Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass. CWE-915--2026-05-21
CVE-2026-8245 Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection CWE-83--2026-05-21
CVE-2026-8337 Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys when sites are running concurrent public surveys and private surveys CWE-639--2026-05-21
CVE-2026-8240 Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure in Backend\SummaryTemplate CWE-284--2026-05-21
CVE-2026-7881 Concrete CMS 9.5.0 and below is vulnerable to IDOR in the Express Entry Detail block CWE-639--2026-05-21
CVE-2026-7879 Concrete CMS 9.5.0 and below is vulnerable to File Download Authorization Bypass in submit_password() CWE-862--2026-05-21
CVE-2026-8238 Concrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/message_page' allowing unauthenticated read of any conversation message CWE-862--2026-05-21

All 72 known CVE vulnerabilities affecting Concrete CMS with full Chinese analysis, references, and POCs where available.