CVEs we hold for Concrete
Records whose assigning authority named Concrete as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-93659Concrete CMS Community Store before 2.7.8 Stored XSSconcretecms-community-store community_store
CVE-2026-87031Missing authorization in the REST API user creation endpoint in Concrete CMS 9.2.0 through 9.5.3 allows arbitrary…Concrete CMS
CVE-2026-87028Cross-Board IDOR in the Board Custom Slot Preview in Concrete CMS 9.0.0 through 9.5.3 Discloses Restricted Page Summary…Concrete CMS
CVE-2026-85387Concrete CMS before 9.5.4 allows a deactivated user to retain OAuth-authenticated REST API accessConcrete CMS
CVE-2026-85386Concrete CMS before 9.5.4 stored is vulneratble to cross-site scripting via unauthenticated XML/XSLT file upload in the…Concrete CMS
CVE-2026-85385Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone FieldConcrete CMS
CVE-2026-84432Concrete CMS 9 through 9.5.2 is vulnerable to CSRFin the Boards custom slot dialog controllerConcrete CMS
CVE-2026-8435Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file…Concrete CMS
CVE-2026-8434Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file…Concrete CMS
CVE-2026-8433Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file…Concrete CMS
CVE-2026-8432Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file…Concrete CMS
CVE-2026-8428CSRF token is not validated in the core CMS update controller for Concrete CMS 9.5.0 and belowConcrete CMS
CVE-2026-8427Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file…Concrete CMS
CVE-2026-8426Concrete CMS 9.5.0 and below is vulnerable to CSRF on prepare_remote_upgrade() leading to one-request RCE via package…Concrete CMS
CVE-2026-8421Concrete CMS 9.5.0 and below is vulnerable to CSRF on install_package() with conditional token bypass leading to RCEConcrete CMS
CVE-2026-8417Concrete CMS 9.5.0 and below is vulnerable to CSRF in do_update() in the package update controllerConcrete CMS
CVE-2026-8416Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file…Concrete CMS
CVE-2026-8415Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at…Concrete CMS
CVE-2026-8414Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at…Concrete CMS
CVE-2026-8413Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at…Concrete CMS
CVE-2026-8412Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at…Concrete CMS
CVE-2026-8411Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at…Concrete CMS
CVE-2026-8410Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at…Concrete CMS
CVE-2026-8409Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at…Concrete CMS
CVE-2026-8353Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in atomik themeConcrete CMS
CVE-2026-8350Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to…Concrete CMS
CVE-2026-8347Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialogConcrete CMS
CVE-2026-8340Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersionConcrete CMS
CVE-2026-8337Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys when sites are running concurrent public surveys and…Concrete CMS
CVE-2026-8327Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening…Concrete CMS
CVE-2026-8245Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injectionConcrete CMS
CVE-2026-8240Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure in Backend\SummaryTemplateConcrete CMS
CVE-2026-8239Concrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/get_rating'Concrete CMS
CVE-2026-8238Concrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/message_page' allowing…Concrete CMS
CVE-2026-8237Concrete CMS 9.5.0 and below is vulnerable to IDOR in the`/ccm/frontend/conversations/message_detail` endpointConcrete CMS
CVE-2026-8236Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate for endpoint…Concrete CMS
CVE-2026-8205Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in Calendar Block since action_get_events does not…Concrete CMS
CVE-2026-8204Concrete CMS 9.5.0 and below is vulnerable to Authorization Bypass in the Calendar Event Frontend DialogConcrete CMS
CVE-2026-8197Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration nameConcrete CMS
CVE-2026-81927Concrete CMS before 9.5.3 is vulnerable to Stored XSS via SVG upload in "Reject" sanitization modeConcrete CMS
CVE-2026-81926Concrete CMS 9.4.0 through 9.5.2 is vulnerable to Cross-site scripting in the location panel duplicate-path…Concrete CMS
CVE-2026-81925Concrete CMS below 9.5.3 is vulnerable to Reflected Cross-Site Scripting (XSS) via Conversation Custom Date FormatConcrete CMS
CVE-2026-81924Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Theme Page Template ActivationConcrete CMS
CVE-2026-81923Concrete CMS below 9.5.3 is missing authorization in the SEO Bulk Update Meta Tags editorConcrete CMS
CVE-2026-81922"In Concrete CMS below 9.5.3, there is Missing authorization in the sitemap page reorder allowing low-privilege users…Concrete CMS
CVE-2026-81921In Concrete CMS 8.5.3 to 9,5,2, OAuth 2.0 Refresh-Token Grant Bypasses Account StatusConcrete CMS
CVE-2026-81920Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Dashboard SEO Excluded Words Reset…Concrete CMS
CVE-2026-81919Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Block Arrangement EndpointConcrete CMS
CVE-2026-81918Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display blockConcrete CMS
CVE-2026-81917Concrete CMS below 9.5.3 is vulnerable to Stored XSS in the Document Library block file description and tagsConcrete CMS
CVE-2026-81916Incorrect Authorization in the Concrete CMS Express Entries Dashboard below version 9.5.3 Allows Entry Creation in an…Concrete CMS
CVE-2026-81915In Concrete CMS below 9.5.3, Page Type update omits object-level authorizationConcrete CMS
CVE-2026-81913Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter.Concrete CMS
CVE-2026-81912Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups featureConcrete CMS
CVE-2026-81911Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot save_template via Unescaped…Concrete CMS
CVE-2026-81910Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated…Concrete CMS
CVE-2026-81909Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block alias route, allowing an…Concrete CMS
CVE-2026-81908Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows Authenticated Users to…Concrete CMS
CVE-2026-81907Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) vin Express delete_entries allowing…Concrete CMS
CVE-2026-81905Concrete CMS below 9.5.3 does not enforce validation-hash type on redemption, allowing a hash issued for one purpose to…Concrete CMS
CVE-2026-81904Concrete CMS before 9.5.3 is vulnerable to Missing Authorization in Stack/Container Sub-Block Asset RegistrationConcrete CMS
CVE-2026-81903Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS via Page Container iconConcrete CMS
CVE-2026-81901Concrete CMS 9.2.0 to 9.5.2 is vulnerable to stored XSS due to missing authorization in the `PUT /pages/{cID}` endpointConcrete CMS
CVE-2026-81900Concrete CMS before 9.5.3 is vulnerable to Stored XSS in the YouTube block (vWidth/vHeight)Concrete CMS
CVE-2026-81899Concrete CMS 9.0 to 9.5.2 is vulnerable to Stored XSS via group folder name on the Members > Groups dashboardConcrete CMS
CVE-2026-81898Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via country-less Address attribute in Express association…Concrete CMS
CVE-2026-81897Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via Express form Text control save_controlConcrete CMS
CVE-2026-81896Concrete CMS below version 9.5.3 is vulnerable to Stored XSS in Concrete CMS Form Submissions Report via Unescaped…Concrete CMS
CVE-2026-81895Concrete CMS 9.5.2 and below is vulnerable to Stored SQL Injection in Concrete CMS Document Library Block via `fsID[]`…Concrete CMS
CVE-2026-81894Concrete CMS 9.5.2 and below is vulnerable to Stored DOM-based Cross-site Scripting (XSS) in the Gallery block image…Concrete CMS
CVE-2026-8140Concrete CMS 9.5.0 and below is vulnerable to CSRF on download() in the package install controllerConcrete CMS
CVE-2026-8139Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvNameConcrete CMS
CVE-2026-8135Concrete CMS 9.5.0 and below is vulnerable to RCE due to insecure deserialization occurring in the ExpressEntryList…Concrete CMS
CVE-2026-8134Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemplate Path Traversal leading to…Concrete CMS
CVE-2026-7888Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and…Concrete CMS
CVE-2026-7887For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account StatusConcrete CMS
CVE-2026-7886Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameterConcrete CMS
CVE-2026-7882Concrete CMS 9.5.0 and below is vulnerable to CSRF via the DeleteFile controllerConcrete CMS
CVE-2026-7881Concrete CMS 9.5.0 and below is vulnerable to IDOR in the Express Entry Detail blockConcrete CMS
CVE-2026-7879Concrete CMS 9.5.0 and below is vulnerable to File Download Authorization Bypass in submit_password()Concrete CMS
CVE-2026-68535Concrete CMS 9.2.0 to 9.5.2 is vulnerable to Missing authorization in the Concrete CMS Area REST API block-create path…Concrete CMS
CVE-2026-68534Concrete CMS below 9.5.2 is vulnerable to Stored XSS via unescaped Express entry labels in association selectorsConcrete CMS
CVE-2026-68533Missing Authorization in Concrete CMS versions below 9.5.3 Conversation File Upload Allows File Import Without the Add…Concrete CMS
CVE-2026-68532Concrete CMS 9.0.0 to 9.5.2 is vunerable to CSRF in Concrete CMS Group Type Deletion Dashboard ActionConcrete CMS
CVE-2026-68531Concrete CMS below 9.5.3 is vulnerable to Authenticated Denial of Service via Unescaped SQL LIKE Wildcards in Keyword…Concrete CMS
CVE-2026-68530Concrete CMS 9.0.0 through 9.5.2 is Missing Authorization on Board Instance Actions Allowed a Board Editor to Access…Concrete CMS
CVE-2026-68529Concrete CMS 9.0.0 through 9.5.2 us missing authorization in the Express entries advanced-search dashboard action…Concrete CMS
CVE-2026-68528Concrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Block via Unescaped Remote Feed Item titleConcrete CMS
CVE-2026-68527Concrete CMS 8.3.0 through 9.5.2 is vulnerable to an authorization bypass through user-controlled key (cross-calendar…Concrete CMS
CVE-2026-68526Concrete CMS before 9.5.3 is vulnerable to CSRF in the Calendar event duplicate dialog controllerConcrete CMS
CVE-2026-6826Concrete 9.5.0 and below has file usage disclosure via missing permission check in Usage controllerConcrete CMS
CVE-2026-3452Concrete CMS below 9.4.8 is vulnerable to stored deserialization leading to RCE in the Express Entry List block.Concrete CMS
CVE-2026-3244Concrete CMS below version 9.4.8 is vulnerable to Stored XSS in Search Results via Page NamesConcrete CMS
CVE-2026-3242Concrete CMS below 9.4.8 is vulnerable to Stored XSS in the Switch Language blockConcrete CMS
CVE-2026-3241Concrete CMS below version 9.4.8 is vulnerable to a stored cross-site scripting (XSS) in the "Legacy Form" block.Concrete CMS
CVE-2026-2994Concrete CMS below 9.4.8 is vulnerable to CSRF by a Rogue Admin using the Anti-Spam Allowlist GroupConcrete CMS
CVE-2026-18426Concrete CMS 9.0.0 to 9.5.2 Express Form block missing authorization allows an authenticated editor to modify Express…Concrete CMS
CVE-2026-18425IDOR in Concrete CMS 9.0.0 through 9.5.2 dashboard sitemap reorder (SitemapUpdate::updateDisplayOrder) allows an…Concrete CMS
CVE-2026-18424Concrete CMS 9.0.0 to 9.5.2 is vulnerable to SSRF protection bypass in remote file import when multiple URLs share a…Concrete CMS
CVE-2026-18423Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search…Concrete CMS
CVE-2026-18422Concrete CMS below 9.5.3 Multilingual Page Assign Action Lacks Destination Authorization and CSRF Token ValidationConcrete CMS
CVE-2026-18421Concrete CMS 9.0.0-9.5.2 Boards data source dashboard is missing an authorization check, allowing a low-privileged…Concrete CMS
CVE-2026-18122Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing AuthorizationConcrete CMS
CVE-2026-18121Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) in the Calendar block's frontend event…Concrete CMS
CVE-2026-18120Missing Authorization in legacy Express entries search endpoint allows disclosure of Express entry dataConcrete CMS
CVE-2026-18119Concrete CMS below 9.5.3 is vulnerable to Stored XSS via unsanitized inline block custom style valuesConcrete CMS
CVE-2026-18117Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Custom Page Alias NameConcrete CMS
CVE-2026-18116Concrete CMS 8.3.0 to 9.5.2 is vulnerable to Stored XSS in Calendar Event Name via Workflow Approval NotificationsConcrete CMS
CVE-2026-18115In Concrete CMS 9.2.0 to 9.5.2, Missing Authorization in REST API Users update() and change_password Enables Account…Concrete CMS
CVE-2026-18113Concrete CMS 9.0 to 9.5.2 is vulnerable to Stored XSS in the Top Navigation Bar Block via Dropdown Child Page NamesConcrete CMS
CVE-2026-18111Concrete CMS below 9.5.4 allows privilege escalation because adding users and assigning groups do not require…Concrete CMS
CVE-2026-18110Concrete CMS 9.0.0 through 9.5.2 is vulnerable to missing authorization in the user selector autocomplete endpoint…Concrete CMS
CVE-2026-10721Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache…Concrete CMS
CVE-2025-8573Concrete CMS 9 through 9.4.2 is vulnerable to Stored XSS from Home Folder on Members Dashboard pageConcrete CMS
CVE-2025-8571Concrete CMS 9 through 9.4.2 and below 8.5.21 is vulnerable to Reflected Cross-Site Scripting (XSS) in Conversation…Concrete CMS
CVE-2025-3153Concrete CMS version 9 below 9.4.0RC2 and versions below 8.5.20 - CSRF and XSS in Concrete CMS Custom Address attributeConcrete CMS
CVE-2024-8661Concrete CMS version 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" blockConcrete CMS
CVE-2024-7394Concrete CMS version 9.0.0 through 9.3.2 and below 8.5.18 - Stored XSS in getAttributeSetName()Concrete CMS
CVE-2024-4350Concrete CMS version 9 below 9.3.3 and below 8.5.18 are vulnerable to Stored XSS in RSS DisplayerConcrete CMS
CVE-2024-3181Concrete CMS version 9 prior to 9.2.8 and previous versions prior to 8.5.16 are vulnerable to Stored XSS in the Search…Concrete CMS
CVE-2024-3180Concrete CMS version 9 below 9.2.8 and previous versions below 8.5.16 is vulnerable to Stored XSS in blocks of type fileConcrete CMS
CVE-2024-3179Concrete CMS version 9 before 9.2.8 and previous versions before 8.5.16 are vulnerable to Stored XSS in the Custom…Concrete CMS
CVE-2024-3178Concrete CMS versions 9 below 9.2.8 and versions below 8.5.16 are vulnerable to Cross-site Scripting (XSS) in the…Concrete CMS
CVE-2024-2753Concrete CMS version 9 below 9.2.8 and below 8.5.16 is vulnerable to stored XSS on the calendar color settings screenConcrete CMS
CVE-2024-2179Concrete CMS version 9 before 9.2.7 is vulnerable to Stored XSS via the Name field of a Group typeConcrete CMS
CVE-2024-1247Concrete CMS version 9 before 9.2.5 vulnerable to stored XSS via the Role Name fieldConcrete CMS
CVE-2024-1246Concrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import FeatureConcrete CMS
CVE-2024-1245Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributesConcrete CMS
140 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.