Exposure of Concrete CMS

CMS
142
exposure score
4,180
sites use
0
exploited
1
critical
Vexday analysis

Com 74 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o Concrete CMS apresenta taxa de exploração abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. O dado mais relevante para atenção é o volume recente: 46 vulnerabilidades surgiram nos últimos 90 dias, sugerindo um ciclo ativo de descoberta e divulgação que demanda acompanhamento contínuo. O tipo de falha mais comum é CWE-352 (Cross-Site Request Forgery), padrão que aponta para fragilidades recorrentes na validação de requisições e que historicamente exige correções consistentes em múltiplos pontos da aplicação. A CVE mais perigosa atualmente, CVE-2024-1247, possui EPSS de 0,0124, refletindo probabilidade ainda baixa de exploração em larga escala, mas sua presença junto à única vulnerabilidade crítica do conjunto recomenda priorização nas equipes de patch management.

CVEs

139 results
CVE-2026-6826MEDIUMConcrete 9.5.0 and below has file usage disclosure via missing permission check in Usage controllerEPSS 1.3%CVE-2024-1247LOWConcrete CMS version 9 before 9.2.5 vulnerable to stored XSS via the Role Name fieldEPSS 1.2%CVE-2026-8134CRITICALConcrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemplate Path Traversal leading to PHP File InclusionEPSS 1.1%CVE-2026-8236MEDIUMConcrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate for endpoint /ccm/system/dialogs/file/usage/{fID}EPSS 0.9%CVE-2026-3452HIGHConcrete CMS below 9.4.8 is vulnerable to stored deserialization leading to RCE in the Express Entry List block.EPSS 0.9%CVE-2026-8135HIGHConcrete CMS 9.5.0 and below is vulnerable to RCE due to insecure deserialization occurring in the ExpressEntryList block controller.EPSS 0.7%CVE-2026-8237MEDIUMConcrete CMS 9.5.0 and below is vulnerable to IDOR in the`/ccm/frontend/conversations/message_detail` endpointEPSS 0.7%CVE-2011-3183—A Cross-Site Scripting (XSS) vulnerability exists in the rcID parameter in Concrete CMS 5.4.1.1 and earlier.EPSS 0.7%CVE-2026-81906MEDIUM[UNREVIEWED] OAuth Callback Login Bypasses Deactivated-Account ChecksEPSS 0.6%CVE-2026-68534LOWConcrete CMS below 9.5.2 is vulnerable to Stored XSS via unescaped Express entry labels in association selectorsEPSS 0.6%CVE-2024-8291MEDIUMConcrete CMS Stored XSS in Image Editor Background ColorEPSS 0.5%CVE-2026-81895HIGHConcrete CMS 9.5.2 and below is vulnerable to Stored SQL Injection in Concrete CMS Document Library Block via `fsID[]` in `setMode=any`EPSS 0.5%CVE-2026-85385HIGHConcrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone FieldEPSS 0.5%CVE-2024-4350MEDIUMConcrete CMS version 9 below 9.3.3 and below 8.5.18 are vulnerable to Stored XSS in RSS DisplayerEPSS 0.5%CVE-2024-7398MEDIUMConcrete CMS Stored XSS Vulnerability in Calendar Event Addition FeatureEPSS 0.5%CVE-2026-81899HIGHConcrete CMS 9.0 to 9.5.2 is vulnerable to Stored XSS via group folder name on the Members > Groups dashboardEPSS 0.5%CVE-2026-8350HIGHConcrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to privilege escalation to Administrative GroupEPSS 0.5%CVE-2026-7886LOWConcrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameterEPSS 0.5%CVE-2026-68527MEDIUMConcrete CMS 8.3.0 through 9.5.2 is vulnerable to an authorization bypass through user-controlled key (cross-calendar IDOR) in the Calendar event edit dialogEPSS 0.5%CVE-2026-68530LOWConcrete CMS 9.0.0 through 9.5.2 is Missing Authorization on Board Instance Actions Allowed a Board Editor to Access and Delete Other Boards' InstancesEPSS 0.5%