Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Concrete CMS — Vulnerabilities & Security Advisories 138

Browse all 138 CVE security advisories affecting Concrete CMS. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Concrete CMS is an open-source content management system designed for building and managing websites, primarily targeting small to medium-sized enterprises and organizations requiring flexible content structures. Historically, its codebase has exhibited vulnerabilities typical of PHP-based applications, including remote code execution, cross-site scripting, and privilege escalation flaws. These issues often stem from insufficient input validation and improper access controls within legacy modules. Security audits have identified multiple critical entries, with twenty-seven CVEs currently on record, reflecting persistent challenges in maintaining secure coding practices across its extensive feature set. Notable incidents involve exploited authentication bypasses and file inclusion errors that allowed unauthorized access to sensitive data. While recent updates have addressed many of these weaknesses, the high volume of historical vulnerabilities underscores the necessity for rigorous code review and continuous security monitoring to mitigate risks associated with its widespread deployment in diverse web environments.

Top products by Concrete CMS: Concrete CMS Concrete CMS
CVE ID Title CVSS Severity Published
CVE-2025-0660 Stored XSS in Folder Function by Rogue Admin — Concrete CMS CWE-20 4.8 - 2025-03-10
CVE-2024-7398 Concrete CMS Stored XSS Vulnerability in Calendar Event Addition Feature — Concrete CMS CWE-79 4.8AI Medium AI 2024-09-24
CVE-2024-8291 Concrete CMS Stored XSS in Image Editor Background Color — Concrete CMS CWE-22 4.8AI Medium AI 2024-09-24
CVE-2024-8660 Stored XSS in the "Top Navigator Bar" block — Concrete CMS CWE-79 4.8 - 2024-09-17
CVE-2024-8661 Concrete CMS version 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" block — Concrete CMS CWE-79 4.8 - 2024-09-16
CVE-2024-4350 Concrete CMS version 9 below 9.3.3 and below 8.5.18 are vulnerable to Stored XSS in RSS Displayer — Concrete CMS CWE-79 4.8AI Medium AI 2024-08-09
CVE-2024-7512 Concrete CMS Stored XSS in Board instances — Concrete CMS CWE-20 4.8AI Medium AI 2024-08-09
CVE-2024-7394 Concrete CMS version 9.0.0 through 9.3.2 and below 8.5.18 - Stored XSS in getAttributeSetName() — Concrete CMS CWE-79 4.8AI Medium AI 2024-08-08
CVE-2024-4353 Stored XSS in Generate Board Name Input Field — Concrete CMS CWE-20 4.8AI Medium AI 2024-08-01
CVE-2024-3181 Concrete CMS version 9 prior to 9.2.8 and previous versions prior to 8.5.16 are vulnerable to Stored XSS in the Search Field. — Concrete CMS CWE-79 3.1 Low 2024-04-03
CVE-2024-3180 Concrete CMS version 9 below 9.2.8 and previous versions below 8.5.16 is vulnerable to Stored XSS in blocks of type file — Concrete CMS CWE-79 3.1 Low 2024-04-03
CVE-2024-3179 Concrete CMS version 9 before 9.2.8 and previous versions before 8.5.16 are vulnerable to Stored XSS in the Custom Class page — Concrete CMS CWE-79 3.1 Low 2024-04-03
CVE-2024-3178 Concrete CMS versions 9 below 9.2.8 and versions below 8.5.16 are vulnerable to Cross-site Scripting (XSS) in the Advanced File Search Filter — Concrete CMS CWE-79 3.1 Low 2024-04-03
CVE-2024-2753 Concrete CMS version 9 below 9.2.8 and below 8.5.16 is vulnerable to stored XSS on the calendar color settings screen — Concrete CMS CWE-79 2.0 Low 2024-04-03
CVE-2024-2179 Concrete CMS version 9 before 9.2.7 is vulnerable to Stored XSS via the Name field of a Group type — Concrete CMS CWE-79 2.2 Low 2024-03-05
CVE-2024-1245 Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributes — Concrete CMS CWE-20 2.4 Low 2024-02-09
CVE-2024-1247 Concrete CMS version 9 before 9.2.5 vulnerable to stored XSS via the Role Name field — Concrete CMS CWE-20 2.0 Low 2024-02-09
CVE-2011-3183 Concrete CMS 跨站脚本漏洞 — Concrete CMS 6.1 - 2020-01-14

This page lists every published CVE security advisory associated with Concrete CMS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.