Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Concrete CMS — Vulnerabilities & Security Advisories 138

Browse all 138 CVE security advisories affecting Concrete CMS. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Concrete CMS is an open-source content management system designed for building and managing websites, primarily targeting small to medium-sized enterprises and organizations requiring flexible content structures. Historically, its codebase has exhibited vulnerabilities typical of PHP-based applications, including remote code execution, cross-site scripting, and privilege escalation flaws. These issues often stem from insufficient input validation and improper access controls within legacy modules. Security audits have identified multiple critical entries, with twenty-seven CVEs currently on record, reflecting persistent challenges in maintaining secure coding practices across its extensive feature set. Notable incidents involve exploited authentication bypasses and file inclusion errors that allowed unauthorized access to sensitive data. While recent updates have addressed many of these weaknesses, the high volume of historical vulnerabilities underscores the necessity for rigorous code review and continuous security monitoring to mitigate risks associated with its widespread deployment in diverse web environments.

Top products by Concrete CMS: Concrete CMS Concrete CMS
CVE ID Title CVSS Severity Published
CVE-2026-18120 Missing Authorization in legacy Express entries search endpoint allows disclosure of Express entry data — Concrete CMS CWE-862 6.3 Medium 2026-09-16
CVE-2026-85387 Concrete CMS before 9.5.4 allows a deactivated user to retain OAuth-authenticated REST API access — Concrete CMS CWE-613 2.0 Low 2026-09-16
CVE-2026-87031 Missing authorization in the REST API user creation endpoint in Concrete CMS 9.2.0 through 9.5.3 allows arbitrary account creation — Concrete CMS CWE-862 2.1 Low 2026-09-16
CVE-2026-87028 Cross-Board IDOR in the Board Custom Slot Preview in Concrete CMS 9.0.0 through 9.5.3 Discloses Restricted Page Summary Fields — Concrete CMS CWE-862 5.3 Medium 2026-09-16
CVE-2026-85386 Concrete CMS before 9.5.4 stored is vulneratble to cross-site scripting via unauthenticated XML/XSLT file upload in the Form Block — Concrete CMS CWE-79 7.3 High 2026-09-16
CVE-2026-85385 Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone Field — Concrete CMS CWE-79 7.7 High 2026-09-16
CVE-2026-81927 Concrete CMS before 9.5.3 is vulnerable to Stored XSS via SVG upload in "Reject" sanitization mode — Concrete CMS CWE-79 1.8 Low 2026-09-15
CVE-2026-18426 Concrete CMS 9.0.0 to 9.5.2 Express Form block missing authorization allows an authenticated editor to modify Express Forms they cannot edit — Concrete CMS CWE-862 2.0 Low 2026-09-15
CVE-2026-81926 Concrete CMS 9.4.0 through 9.5.2 is vulnerable to Cross-site scripting in the location panel duplicate-path confirmation dialog — Concrete CMS CWE-79 2.0 Low 2026-09-15
CVE-2026-81925 Concrete CMS below 9.5.3 is vulnerable to Reflected Cross-Site Scripting (XSS) via Conversation Custom Date Format — Concrete CMS CWE-79 2.1 Low 2026-09-15
CVE-2026-18425 IDOR in Concrete CMS 9.0.0 through 9.5.2 dashboard sitemap reorder (SitemapUpdate::updateDisplayOrder) allows an authenticated sitemap user to reorder arbitrary pages — Concrete CMS CWE-862 2.1 Low 2026-09-15
CVE-2026-18424 Concrete CMS 9.0.0 to 9.5.2 is vulnerable to SSRF protection bypass in remote file import when multiple URLs share a host but use different ports — Concrete CMS CWE-918 2.1 Low 2026-09-15
CVE-2026-18423 Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs allowing an authenticated user with permission on one Express entity to delete or rename saved search pres — Concrete CMS CWE-639 2.1 Low 2026-09-15
CVE-2026-18422 Concrete CMS below 9.5.3 Multilingual Page Assign Action Lacks Destination Authorization and CSRF Token Validation — Concrete CMS CWE-862 2.1 Low 2026-09-15
CVE-2026-18421 Concrete CMS 9.0.0-9.5.2 Boards data source dashboard is missing an authorization check, allowing a low-privileged board editor to modify or delete configured data sources on boards they do not control — Concrete CMS CWE-862 2.1 Low 2026-09-15
CVE-2026-68529 Concrete CMS 9.0.0 through 9.5.2 us missing authorization in the Express entries advanced-search dashboard action allowing a low-privileged user to read other entities' Express entries — Concrete CMS CWE-862 2.1 Low 2026-09-15
CVE-2026-68530 Concrete CMS 9.0.0 through 9.5.2 is Missing Authorization on Board Instance Actions Allowed a Board Editor to Access and Delete Other Boards' Instances — Concrete CMS CWE-862 2.1 Low 2026-09-15
CVE-2026-68531 Concrete CMS below 9.5.3 is vulnerable to Authenticated Denial of Service via Unescaped SQL LIKE Wildcards in Keyword Search — Concrete CMS CWE-405 2.1 Low 2026-09-15
CVE-2026-81924 Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Theme Page Template Activation — Concrete CMS CWE-352 2.1 Low 2026-09-15
CVE-2026-81923 Concrete CMS below 9.5.3 is missing authorization in the SEO Bulk Update Meta Tags editor — Concrete CMS CWE-862 2.1 Low 2026-09-15
CVE-2026-81922 "In Concrete CMS below 9.5.3, there is Missing authorization in the sitemap page reorder allowing low-privilege users to reorder arbitrary pages " — Concrete CMS CWE-862 2.1 Low 2026-09-15
CVE-2026-81921 In Concrete CMS 8.5.3 to 9,5,2, OAuth 2.0 Refresh-Token Grant Bypasses Account Status — Concrete CMS CWE-862 2.3 Low 2026-09-15
CVE-2026-81920 Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Dashboard SEO Excluded Words Reset Endpoint — Concrete CMS CWE-352 2.3 Low 2026-09-15
CVE-2026-68532 Concrete CMS 9.0.0 to 9.5.2 is vunerable to CSRF in Concrete CMS Group Type Deletion Dashboard Action — Concrete CMS CWE-352 2.3 Low 2026-09-15
CVE-2026-68533 Missing Authorization in Concrete CMS versions below 9.5.3 Conversation File Upload Allows File Import Without the Add Message Attachments Permission — Concrete CMS CWE-862 2.3 Low 2026-09-15
CVE-2026-68534 Concrete CMS below 9.5.2 is vulnerable to Stored XSS via unescaped Express entry labels in association selectors — Concrete CMS CWE-79 2.3 Low 2026-09-15
CVE-2026-81919 Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Block Arrangement Endpoint — Concrete CMS CWE-352 2.3 Low 2026-09-15
CVE-2026-81899 Concrete CMS 9.0 to 9.5.2 is vulnerable to Stored XSS via group folder name on the Members > Groups dashboard — Concrete CMS CWE-79 7.3 High 2026-09-15
CVE-2026-18115 In Concrete CMS 9.2.0 to 9.5.2, Missing Authorization in REST API Users update() and change_password Enables Account Takeover. — Concrete CMS CWE-862 7.4 High 2026-09-15
CVE-2026-18113 Concrete CMS 9.0 to 9.5.2 is vulnerable to Stored XSS in the Top Navigation Bar Block via Dropdown Child Page Names — Concrete CMS CWE-79 7.5 High 2026-09-15

This page lists every published CVE security advisory associated with Concrete CMS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.