Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Concrete CMS — Vulnerabilities & Security Advisories 138

Browse all 138 CVE security advisories affecting Concrete CMS. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Concrete CMS is an open-source content management system designed for building and managing websites, primarily targeting small to medium-sized enterprises and organizations requiring flexible content structures. Historically, its codebase has exhibited vulnerabilities typical of PHP-based applications, including remote code execution, cross-site scripting, and privilege escalation flaws. These issues often stem from insufficient input validation and improper access controls within legacy modules. Security audits have identified multiple critical entries, with twenty-seven CVEs currently on record, reflecting persistent challenges in maintaining secure coding practices across its extensive feature set. Notable incidents involve exploited authentication bypasses and file inclusion errors that allowed unauthorized access to sensitive data. While recent updates have addressed many of these weaknesses, the high volume of historical vulnerabilities underscores the necessity for rigorous code review and continuous security monitoring to mitigate risks associated with its widespread deployment in diverse web environments.

Top products by Concrete CMS: Concrete CMS Concrete CMS
CVE ID Title CVSS Severity Published
CVE-2026-81905 Concrete CMS below 9.5.3 does not enforce validation-hash type on redemption, allowing a hash issued for one purpose to be redeemed for another. — Concrete CMS CWE-863 6.3 Medium 2026-09-10
CVE-2026-18121 Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) in the Calendar block's frontend event dialog (/ccm/calendar/view_event/{bID}/{occurrence_id}). — Concrete CMS CWE-862 6.3 Medium 2026-09-10
CVE-2026-84432 Concrete CMS 9 through 9.5.2 is vulnerable to CSRFin the Boards custom slot dialog controller — Concrete CMS CWE-352 5.3 Medium 2026-09-10
CVE-2026-68527 Concrete CMS 8.3.0 through 9.5.2 is vulnerable to an authorization bypass through user-controlled key (cross-calendar IDOR) in the Calendar event edit dialog — Concrete CMS CWE-639 5.9 Medium 2026-09-10
CVE-2026-81904 Concrete CMS before 9.5.3 is vulnerable to Missing Authorization in Stack/Container Sub-Block Asset Registration — Concrete CMS CWE-862 6.3 Medium 2026-09-08
CVE-2026-10721 Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and Search components — Concrete CMS CWE-502 - - 2026-06-10
CVE-2026-7888 Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. — Concrete CMS CWE-502 8.4 High 2026-06-03
CVE-2026-8353 Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in atomik theme — Concrete CMS CWE-79 - - 2026-05-22
CVE-2026-8347 Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialog — Concrete CMS CWE-639 - - 2026-05-22
CVE-2026-8340 Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion — Concrete CMS CWE-352 - - 2026-05-22
CVE-2026-8139 Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName — Concrete CMS CWE-79 - - 2026-05-21
CVE-2026-7890 Concrete CMS 9.5.0 is vulnerable to SSRF via RSS Displayer Block — Concrete CMS CWE-918 - - 2026-05-21
CVE-2026-8409 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete — Concrete CMS CWE-352 - - 2026-05-21
CVE-2026-8410 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete — Concrete CMS CWE-352 - - 2026-05-21
CVE-2026-8411 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete — Concrete CMS CWE-352 - - 2026-05-21
CVE-2026-8412 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache — Concrete CMS CWE-352 - - 2026-05-21
CVE-2026-8413 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design — Concrete CMS CWE-352 - - 2026-05-21
CVE-2026-8414 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate — Concrete CMS CWE-352 - - 2026-05-21
CVE-2026-8415 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder — Concrete CMS CWE-352 - - 2026-05-21
CVE-2026-8416 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id) — Concrete CMS CWE-352 - - 2026-05-21
CVE-2026-8427 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id) — Concrete CMS CWE-352 - - 2026-05-21
CVE-2026-8432 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star() — Concrete CMS CWE-352 - - 2026-05-21
CVE-2026-8433 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan() — Concrete CMS CWE-352 - - 2026-05-21
CVE-2026-8434 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple() — Concrete CMS CWE-352 - - 2026-05-21
CVE-2026-8435 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion() — Concrete CMS CWE-352 - - 2026-05-21
CVE-2026-7887 For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status — Concrete CMS CWE-1287 - - 2026-05-21
CVE-2026-7886 Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter — Concrete CMS CWE-639 - - 2026-05-21
CVE-2026-7882 Concrete CMS 9.5.0 and below is vulnerable to CSRF via the DeleteFile controller — Concrete CMS CWE-352 - - 2026-05-21
CVE-2026-8327 Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass. — Concrete CMS CWE-915 - - 2026-05-21
CVE-2026-8245 Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection — Concrete CMS CWE-83 - - 2026-05-21

This page lists every published CVE security advisory associated with Concrete CMS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.