Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Concrete CMS — Vulnerabilities & Security Advisories 72

All 72 CVE vulnerabilities found in Concrete CMS, with AI-generated Chinese analysis, references, and POCs.

This page details security vulnerabilities, weaknesses, and associated tags for the Concrete CMS product. It aggregates data related to common flaw types found within this content management system, providing a centralized view of known security issues. The content includes a comprehensive collection of reported vulnerabilities affecting Concrete CMS, covering incidents identified from the system's inception through the most recent updates. By reviewing this aggregated data, users can effectively track vendor advisories to stay informed about critical patches and security notices. Readers can also use this resource to understand specific weakness classes that impact the platform, allowing for better risk assessment and mitigation strategies. Furthermore, the page serves as a historical record, enabling users to look up a product's vulnerability history over time. This continuity helps in identifying patterns, assessing the long-term security posture of Concrete CMS, and understanding how previous issues have been addressed. The information presented is strictly technical and factual, designed to assist security professionals, developers, and administrators in maintaining the integrity and safety of their deployments. There is no promotional content or marketing language included in this summary. The focus remains entirely on the technical aspects of vulnerability management and the specific security challenges associated with Concrete CMS.

Vendor: Concrete CMS

CVE IDTitleCVSSSeverityPublished
CVE-2024-4350 Concrete CMS version 9 below 9.3.3 and below 8.5.18 are vulnerable to Stored XSS in RSS Displayer CWE-79 4.8AIMediumAI2024-08-09
CVE-2024-7512 Concrete CMS Stored XSS in Board instances CWE-20 4.8AIMediumAI2024-08-09
CVE-2024-7394 Concrete CMS version 9.0.0 through 9.3.2 and below 8.5.18 - Stored XSS in getAttributeSetName() CWE-79 4.8AIMediumAI2024-08-08
CVE-2024-4353 Stored XSS in Generate Board Name Input Field CWE-20 4.8AIMediumAI2024-08-01
CVE-2024-3181 Concrete CMS version 9 prior to 9.2.8 and previous versions prior to 8.5.16 are vulnerable to Stored XSS in the Search Field. CWE-79 3.1 Low2024-04-03
CVE-2024-3180 Concrete CMS version 9 below 9.2.8 and previous versions below 8.5.16 is vulnerable to Stored XSS in blocks of type file CWE-79 3.1 Low2024-04-03
CVE-2024-3179 Concrete CMS version 9 before 9.2.8 and previous versions before 8.5.16 are vulnerable to Stored XSS in the Custom Class page CWE-79 3.1 Low2024-04-03
CVE-2024-3178 Concrete CMS versions 9 below 9.2.8 and versions below 8.5.16 are vulnerable to Cross-site Scripting (XSS) in the Advanced File Search Filter CWE-79 3.1 Low2024-04-03
CVE-2024-2753 Concrete CMS version 9 below 9.2.8 and below 8.5.16 is vulnerable to stored XSS on the calendar color settings screen CWE-79 2.0 Low2024-04-03
CVE-2024-2179 Concrete CMS version 9 before 9.2.7 is vulnerable to Stored XSS via the Name field of a Group type CWE-79 2.2 Low2024-03-05
CVE-2024-1247 Concrete CMS version 9 before 9.2.5 vulnerable to stored XSS via the Role Name field CWE-20 2.0 Low2024-02-09
CVE-2011-3183 Concrete CMS 跨站脚本漏洞 6.1 -2020-01-14

All 72 known CVE vulnerabilities affecting Concrete CMS with full Chinese analysis, references, and POCs where available.