Exposure of Concrete CMS

CMS
142
exposure score
4,180
sites use
0
exploited
1
critical
Vexday analysis

Com 74 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o Concrete CMS apresenta taxa de exploração abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. O dado mais relevante para atenção é o volume recente: 46 vulnerabilidades surgiram nos últimos 90 dias, sugerindo um ciclo ativo de descoberta e divulgação que demanda acompanhamento contínuo. O tipo de falha mais comum é CWE-352 (Cross-Site Request Forgery), padrão que aponta para fragilidades recorrentes na validação de requisições e que historicamente exige correções consistentes em múltiplos pontos da aplicação. A CVE mais perigosa atualmente, CVE-2024-1247, possui EPSS de 0,0124, refletindo probabilidade ainda baixa de exploração em larga escala, mas sua presença junto à única vulnerabilidade crítica do conjunto recomenda priorização nas equipes de patch management.

CVEs

139 results
CVE-2026-18110HIGHConcrete CMS 9.0.0 through 9.5.2 is vulnerable to missing authorization in the user selector autocomplete endpoint (/ccm/system/user/autocomplete), allowing an unauthenticated attacker to retrieve the complete backend user directory — internal ID, usernameEPSS 0.3%CVE-2026-8426HIGHConcrete CMS 9.5.0 and below is vulnerable to CSRF on prepare_remote_upgrade() leading to one-request RCE via package overwriteEPSS 0.3%CVE-2026-8421HIGHConcrete CMS 9.5.0 and below is vulnerable to CSRF on install_package() with conditional token bypass leading to RCEEPSS 0.3%CVE-2026-85387LOWConcrete CMS before 9.5.4 allows a deactivated user to retain OAuth-authenticated REST API accessEPSS 0.3%CVE-2026-18115HIGHIn Concrete CMS 9.2.0 to 9.5.2, Missing Authorization in REST API Users update() and change_password Enables Account Takeover.EPSS 0.3%CVE-2026-81900HIGHConcrete CMS before 9.5.3 is vulnerable to Stored XSS in the YouTube block (vWidth/vHeight)EPSS 0.3%CVE-2026-81926LOWConcrete CMS 9.4.0 through 9.5.2 is vulnerable to Cross-site scripting in the location panel duplicate-path confirmation dialogEPSS 0.3%CVE-2026-8197HIGHConcrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration nameEPSS 0.3%CVE-2026-81918MEDIUMConcrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display blockEPSS 0.3%CVE-2026-8353LOWConcrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in atomik themeEPSS 0.3%CVE-2026-8139LOWConcrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvNameEPSS 0.3%CVE-2026-7890LOWConcrete CMS 9.5.0 is vulnerable to SSRF via RSS Displayer BlockEPSS 0.2%CVE-2026-18423LOWConcrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs allowing an authenticated user with permission on one Express entity to delete or rename saved search presEPSS 0.2%CVE-2026-81902HIGHConcrete CMS 9.0.0 to 9.5.2 is vulnerable to CSRF on Orphan Block CleanupEPSS 0.2%CVE-2026-84432MEDIUMConcrete CMS 9 through 9.5.2 is vulnerable to CSRFin the Boards custom slot dialog controllerEPSS 0.2%CVE-2026-81921LOWIn Concrete CMS 8.5.3 to 9,5,2, OAuth 2.0 Refresh-Token Grant Bypasses Account StatusEPSS 0.2%CVE-2026-18424LOWConcrete CMS 9.0.0 to 9.5.2 is vulnerable to SSRF protection bypass in remote file import when multiple URLs share a host but use different portsEPSS 0.2%CVE-2026-81894HIGHConcrete CMS 9.5.2 and below is vulnerable to Stored DOM-based Cross-site Scripting (XSS) in the Gallery block image Caption fieldEPSS 0.2%CVE-2026-81896HIGHConcrete CMS below version 9.5.3 is vulnerable to Stored XSS in Concrete CMS Form Submissions Report via Unescaped Question LabelEPSS 0.2%CVE-2026-81911MEDIUMConcrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot save_template via Unescaped Summary DescriptionEPSS 0.2%