Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Concrete CMS — Vulnerabilities & Security Advisories 138

Browse all 138 CVE security advisories affecting Concrete CMS. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Concrete CMS is an open-source content management system designed for building and managing websites, primarily targeting small to medium-sized enterprises and organizations requiring flexible content structures. Historically, its codebase has exhibited vulnerabilities typical of PHP-based applications, including remote code execution, cross-site scripting, and privilege escalation flaws. These issues often stem from insufficient input validation and improper access controls within legacy modules. Security audits have identified multiple critical entries, with twenty-seven CVEs currently on record, reflecting persistent challenges in maintaining secure coding practices across its extensive feature set. Notable incidents involve exploited authentication bypasses and file inclusion errors that allowed unauthorized access to sensitive data. While recent updates have addressed many of these weaknesses, the high volume of historical vulnerabilities underscores the necessity for rigorous code review and continuous security monitoring to mitigate risks associated with its widespread deployment in diverse web environments.

Top products by Concrete CMS: Concrete CMS Concrete CMS
CVE ID Title CVSS Severity Published
CVE-2026-81898 Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via country-less Address attribute in Express association views — Concrete CMS CWE-79 7.5 High 2026-09-15
CVE-2026-81897 Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via Express form Text control save_control — Concrete CMS CWE-352 7.7 High 2026-09-15
CVE-2026-81896 Concrete CMS below version 9.5.3 is vulnerable to Stored XSS in Concrete CMS Form Submissions Report via Unescaped Question Label — Concrete CMS CWE-79 8.4 High 2026-09-15
CVE-2026-18111 Concrete CMS below 9.5.4 allows privilege escalation because adding users and assigning groups do not require additional identity verification — Concrete CMS CWE-306 8.5 High 2026-09-15
CVE-2026-81895 Concrete CMS 9.5.2 and below is vulnerable to Stored SQL Injection in Concrete CMS Document Library Block via `fsID[]` in `setMode=any` — Concrete CMS CWE-89 8.5 High 2026-09-15
CVE-2026-81894 Concrete CMS 9.5.2 and below is vulnerable to Stored DOM-based Cross-site Scripting (XSS) in the Gallery block image Caption field — Concrete CMS CWE-89 8.5 High 2026-09-15
CVE-2026-18110 Concrete CMS 9.0.0 through 9.5.2 is vulnerable to missing authorization in the user selector autocomplete endpoint (/ccm/system/user/autocomplete), allowing an unauthenticated attacker to retrieve the complete backend user directory — internal ID, username — Concrete CMS CWE-862 8.7 High 2026-09-15
CVE-2026-81900 Concrete CMS before 9.5.3 is vulnerable to Stored XSS in the YouTube block (vWidth/vHeight) — Concrete CMS CWE-79 7.3 High 2026-09-14
CVE-2026-18116 Concrete CMS 8.3.0 to 9.5.2 is vulnerable to Stored XSS in Calendar Event Name via Workflow Approval Notifications — Concrete CMS CWE-79 7.3 High 2026-09-14
CVE-2026-18117 Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Custom Page Alias Name — Concrete CMS CWE-79 7.3 High 2026-09-14
CVE-2026-81901 Concrete CMS 9.2.0 to 9.5.2 is vulnerable to stored XSS due to missing authorization in the `PUT /pages/{cID}` endpoint — Concrete CMS CWE-862 7.2 High 2026-09-14
CVE-2026-81902 Concrete CMS 9.0.0 to 9.5.2 is vulnerable to CSRF on Orphan Block Cleanup — Concrete CMS CWE-352 7.1 High 2026-09-14
CVE-2026-81903 Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS via Page Container icon — Concrete CMS CWE-79 7.0 High 2026-09-14
CVE-2026-18119 Concrete CMS below 9.5.3 is vulnerable to Stored XSS via unsanitized inline block custom style values — Concrete CMS CWE-79 7.0 High 2026-09-14
CVE-2026-81907 Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) vin Express delete_entries allowing mass deletion of all entity records — Concrete CMS CWE-352 6.1 Medium 2026-09-11
CVE-2026-81918 Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block — Concrete CMS CWE-79 4.8 Medium 2026-09-11
CVE-2026-81917 Concrete CMS below 9.5.3 is vulnerable to Stored XSS in the Document Library block file description and tags — Concrete CMS CWE-79 5.1 Medium 2026-09-11
CVE-2026-68535 Concrete CMS 9.2.0 to 9.5.2 is vulnerable to Missing authorization in the Concrete CMS Area REST API block-create path letting an editor reference files outside their file-manager permissions — Concrete CMS CWE-862 5.1 Medium 2026-09-11
CVE-2026-81916 Incorrect Authorization in the Concrete CMS Express Entries Dashboard below version 9.5.3 Allows Entry Creation in an Unauthorized Object — Concrete CMS CWE-862 5.1 Medium 2026-09-11
CVE-2026-81915 In Concrete CMS below 9.5.3, Page Type update omits object-level authorization — Concrete CMS CWE-862 5.1 Medium 2026-09-11
CVE-2026-68526 Concrete CMS before 9.5.3 is vulnerable to CSRF in the Calendar event duplicate dialog controller — Concrete CMS CWE-352 5.3 Medium 2026-09-11
CVE-2026-81913 Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. — Concrete CMS CWE-601 5.3 Medium 2026-09-11
CVE-2026-81912 Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature — Concrete CMS CWE-352 5.7 Medium 2026-09-11
CVE-2026-81911 Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot save_template via Unescaped Summary Description — Concrete CMS CWE-79 5.8 Medium 2026-09-11
CVE-2026-81910 Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values — Concrete CMS CWE-1336 5.9 Medium 2026-09-11
CVE-2026-81909 Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block alias route, allowing an authenticated editor to disclose and force-delete arbitrary blocks — Concrete CMS CWE-862 5.9 Medium 2026-09-11
CVE-2026-68528 Concrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Block via Unescaped Remote Feed Item title — Concrete CMS CWE-79 6.0 Medium 2026-09-11
CVE-2026-18122 Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization — Concrete CMS CWE-862 6.0 Medium 2026-09-11
CVE-2026-81908 Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows Authenticated Users to Enumerate All Groups — Concrete CMS CWE-862 6.0 Medium 2026-09-11
CVE-2026-81906 [UNREVIEWED] OAuth Callback Login Bypasses Deactivated-Account Checks — Concrete CMS CWE-288 6.3 Medium 2026-09-10

This page lists every published CVE security advisory associated with Concrete CMS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.