Concrete CMS
65 known vulnerabilities in Concrete CMS, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-85387 CVSS 2.0 low Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-check the state of the account…
- CVE-2026-18120 CVSS 6.3 medium Concrete CMS before 9.5.3 exposed a legacy Express entry search endpoint that returned entry result JSON without invoking the…
- CVE-2026-87031 CVSS 2.1 low n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation endpoint (POST /ccm/api/1.0/users, the add() method of…
- CVE-2026-87028 CVSS 5.3 medium Concrete CMS 9 through 9.5.3 did not confirm that a board InstanceItem submitted to the custom-slot preview endpoint belonged to the board…
- CVE-2026-85386 CVSS 7.3 high Concrete CMS before 9.5.4 did not sanitize XML and XSLT documents uploaded through a public Form Block file-upload question. Plain XML…
- CVE-2026-85385 CVSS 7.7 high Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output encoding on the…
- CVE-2026-81927 CVSS 1.8 low Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling. When SVG processing was set to the…
- CVE-2026-81926 CVSS 2.0 low Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's duplicate-path…
- CVE-2026-18426 CVSS 2.0 low Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level edit-permission check on the Express Form block's control-management…
- CVE-2026-81925 CVSS 2.1 low Concrete CMS before 9.5.3 improperly neutralized a user-supplied custom date format when rendering conversation messages, resulting in…
- CVE-2026-18425 CVSS 2.1 low Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap reorder action (Concrete\Controller\Backend\Dashboard\SitemapUpdate) using…
- CVE-2026-18424 CVSS 2.1 low Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side Request Forgery iremote file import via cross-port reuse of a host's validated…
- CVE-2026-18423 CVSS 2.1 low Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and…
- CVE-2026-18422 CVSS 2.1 low Concrete CMS before 9.5.3 did not enforce a destination-side authorization check and did not validate a CSRF token in the multilingual…
- CVE-2026-81924 CVSS 2.1 low Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in the theme page-template activation feature. The Dashboard…
- CVE-2026-81923 CVSS 2.1 low In Concrete CMS before 9.5.3, the SEO Bulk Update Meta Tags editor did not check per-page edit permissions before saving. The saveRecord()…
- CVE-2026-81922 CVSS 2.1 low Concrete CMS before 9.5.3 did not enforce a per-page authorization check when reordering pages from the sitemap. In the sitemap Explore…
- CVE-2026-81921 CVSS 2.3 low Concrete CMS 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token grant using the unmodified upstream League grant, which issued new…
- CVE-2026-81920 CVSS 2.3 low Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page. The reset() controller…
- CVE-2026-81919 CVSS 2.3 low Concrete CMS below 9.5.3 did not validate an anti-CSRF token on the block-arrangement backend endpoint (the arrange() action of…
- CVE-2026-68534 CVSS 2.3 low Concrete CMS before 9.5.3 rendered Express entry labels as raw HTML when displaying associated entries, resulting in stored cross-site…
- CVE-2026-68533 CVSS 2.3 low Concrete CMS below 9.5.3 conversation attachment uploaded endpoint imported files into the file manager before evaluating the "Add Message…
- CVE-2026-68532 CVSS 2.3 low Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cross-site request…
- CVE-2026-68531 CVSS 2.1 low Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard characters in the keyword search filters used by the file manager, file…
- CVE-2026-68530 CVSS 2.1 low Concrete CMS 9 through 9.5.2 did not perform an authorization check on several board-instance actions in the Boards area of the Dashboard…
- CVE-2026-68529 CVSS 2.1 low Concrete CMS 9.0.0 through 9.5.2 was missing an authorization check on the Express entries advanced-search dashboard action. The…
- CVE-2026-18421 CVSS 2.1 low Concrete CMS 9 through 9.5.2 does not perform an authorization check in three actions of the Boards data source dashboard controller…
- CVE-2026-81899 CVSS 7.3 high Concrete CMS 9.0.0 to 9.5.2 stored group folder names without sanitization and printed them unescaped on the Members > Groups dashboard…
- CVE-2026-81898 CVSS 7.5 high In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stored XSS in…
- CVE-2026-18115 CVSS 7.4 high Concrete CMS 9.2.0 to 9.5.2 did not enforce per-field edit_user_properties permissions on the REST API user write endpoints (PUT…