Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Concrete CMS — Vulnerabilities & Security Advisories 73

Browse all 73 CVE security advisories affecting Concrete CMS. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Concrete CMS is an open-source content management system designed for building and managing websites, primarily targeting small to medium-sized enterprises and organizations requiring flexible content structures. Historically, its codebase has exhibited vulnerabilities typical of PHP-based applications, including remote code execution, cross-site scripting, and privilege escalation flaws. These issues often stem from insufficient input validation and improper access controls within legacy modules. Security audits have identified multiple critical entries, with twenty-seven CVEs currently on record, reflecting persistent challenges in maintaining secure coding practices across its extensive feature set. Notable incidents involve exploited authentication bypasses and file inclusion errors that allowed unauthorized access to sensitive data. While recent updates have addressed many of these weaknesses, the high volume of historical vulnerabilities underscores the necessity for rigorous code review and continuous security monitoring to mitigate risks associated with its widespread deployment in diverse web environments.

Found 72 results / 73Clear Filters
Top products by Concrete CMS: Concrete CMS Concrete CMS
CVE IDTitleCVSSSeverityPublished
CVE-2026-8237 Concrete CMS 9.5.0 and below is vulnerable to IDOR in the`/ccm/frontend/conversations/message_detail` endpoint — Concrete CMSCWE-862--2026-05-21
CVE-2026-8239 Concrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/get_rating' — Concrete CMSCWE-862--2026-05-21
CVE-2026-8236 Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate for endpoint /ccm/system/dialogs/file/usage/{fID} — Concrete CMSCWE-862--2026-05-21
CVE-2026-8205 Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in Calendar Block since action_get_events does not check canView on the calendar — Concrete CMSCWE-425--2026-05-21
CVE-2026-8204 Concrete CMS 9.5.0 and below is vulnerable to Authorization Bypass in the Calendar Event Frontend Dialog — Concrete CMSCWE-639--2026-05-21
CVE-2026-6826 Concrete 9.5.0 and below has file usage disclosure via missing permission check in Usage controller — Concrete CMSCWE-200--2026-05-21
CVE-2026-8203 Concrete CMS 9.5.0 and below has Stored XSS on the height parameter — Concrete CMSCWE-79--2026-05-21
CVE-2026-8197 Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration name — Concrete CMSCWE-79--2026-05-21
CVE-2026-8350 Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to privilege escalation to Administrative Group — Concrete CMSCWE-863--2026-05-21
CVE-2026-8421 Concrete CMS 9.5.0 and below is vulnerable to CSRF on install_package() with conditional token bypass leading to RCE — Concrete CMSCWE-352--2026-05-21
CVE-2026-8428 CSRF token is not validated in the core CMS update controller for Concrete CMS 9.5.0 and below — Concrete CMSCWE-352--2026-05-21
CVE-2026-8426 Concrete CMS 9.5.0 and below is vulnerable to CSRF on prepare_remote_upgrade() leading to one-request RCE via package overwrite — Concrete CMSCWE-352--2026-05-21
CVE-2026-8140 Concrete CMS 9.5.0 and below is vulnerable to CSRF on download() in the package install controller — Concrete CMSCWE-352--2026-05-21
CVE-2026-8417 Concrete CMS 9.5.0 and below is vulnerable to CSRF in do_update() in the package update controller — Concrete CMSCWE-352--2026-05-21
CVE-2026-8135 Concrete CMS 9.5.0 and below is vulnerable to RCE due to insecure deserialization occurring in the ExpressEntryList block controller. — Concrete CMSCWE-502--2026-05-21
CVE-2026-8134 Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemplate Path Traversal leading to PHP File Inclusion — Concrete CMSCWE-98--2026-05-21
CVE-2026-2994 Concrete CMS below 9.4.8 is vulnerable to CSRF by a Rogue Admin using the Anti-Spam Allowlist Group — Concrete CMSCWE-352 6.8 -2026-03-04
CVE-2026-3240 Concrete CMS below 9.4.8 is vulnerable to Stored XSS via Legacy form — Concrete CMSCWE-79 5.4 -2026-03-04
CVE-2026-3241 Concrete CMS below version 9.4.8 is vulnerable to a stored cross-site scripting (XSS) in the "Legacy Form" block. — Concrete CMSCWE-79 4.8 -2026-03-04
CVE-2026-3242 Concrete CMS below 9.4.8 is vulnerable to Stored XSS in the Switch Language block — Concrete CMSCWE-79 4.8 -2026-03-04
CVE-2026-3244 Concrete CMS below version 9.4.8 is vulnerable to Stored XSS in Search Results via Page Names — Concrete CMSCWE-79 4.8 -2026-03-04
CVE-2026-3452 Concrete CMS below 9.4.8 is vulnerable to stored deserialization leading to RCE in the Express Entry List block. — Concrete CMSCWE-502 7.2 -2026-03-04
CVE-2025-8571 Concrete CMS 9 through 9.4.2 and below 8.5.21 is vulnerable to Reflected Cross-Site Scripting (XSS) in Conversation Messages Dashboard Page — Concrete CMSCWE-20 6.1AIMediumAI2025-08-05
CVE-2025-8573 Concrete CMS 9 through 9.4.2 is vulnerable to Stored XSS from Home Folder on Members Dashboard page — Concrete CMSCWE-20 4.8AIMediumAI2025-08-05
CVE-2025-3153 Concrete CMS version 9 below 9.4.0RC2 and versions below 8.5.20 - CSRF and XSS in Concrete CMS Custom Address attribute — Concrete CMSCWE-79 5.4AIMediumAI2025-04-03
CVE-2025-0660 Stored XSS in Folder Function by Rogue Admin — Concrete CMSCWE-20 4.8 -2025-03-10
CVE-2024-7398 Concrete CMS Stored XSS Vulnerability in Calendar Event Addition Feature — Concrete CMSCWE-79 4.8AIMediumAI2024-09-24
CVE-2024-8291 Concrete CMS Stored XSS in Image Editor Background Color — Concrete CMSCWE-22 4.8AIMediumAI2024-09-24
CVE-2024-8660 Stored XSS in the "Top Navigator Bar" block — Concrete CMSCWE-79 4.8 -2024-09-17
CVE-2024-8661 Concrete CMS version 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" block — Concrete CMSCWE-79 4.8 -2024-09-16

This page lists every published CVE security advisory associated with Concrete CMS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.