Vulnerabilities in Concrete CMS

139 results
Vexday analysis

Com 74 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o Concrete CMS apresenta taxa de exploração abaixo da média geral do catálogo, o que sugere menor pressão imediata de ataques oportunistas. No entanto, chama atenção o volume expressivo de 46 vulnerabilidades surgidas nos últimos 90 dias, indicando aceleração recente no ritmo de descoberta de falhas. O tipo de falha mais comum é CWE-352 (Cross-Site Request Forgery), padrão que tende a refletir deficiências estruturais na validação de requisições e merece atenção no processo de revisão de código. A CVE mais perigosa atualmente rastreada, CVE-2024-1247, possui EPSS de 0,0124, sinalizando probabilidade baixa de exploração em curto prazo, mas deve ser monitorada, especialmente diante do único CVE de severidade crítica presente no conjunto.

CVE-2026-68530LOWConcrete CMS 9.0.0 through 9.5.2 is Missing Authorization on Board Instance Actions Allowed a Board Editor to Access and Delete Other Boards' InstancesEPSS 0.5%CVE-2026-68531LOWConcrete CMS below 9.5.3 is vulnerable to Authenticated Denial of Service via Unescaped SQL LIKE Wildcards in Keyword SearchEPSS 0.5%CVE-2026-81904MEDIUMConcrete CMS before 9.5.3 is vulnerable to Missing Authorization in Stack/Container Sub-Block Asset RegistrationEPSS 0.5%CVE-2024-1246LOWConcrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import FeatureEPSS 0.5%CVE-2026-18422LOWConcrete CMS below 9.5.3 Multilingual Page Assign Action Lacks Destination Authorization and CSRF Token ValidationEPSS 0.4%CVE-2026-68535MEDIUMConcrete CMS 9.2.0 to 9.5.2 is vulnerable to Missing authorization in the Concrete CMS Area REST API block-create path letting an editor reference files outside their file-manager permissionsEPSS 0.4%CVE-2024-8661MEDIUMConcrete CMS version 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" blockEPSS 0.4%CVE-2026-81909MEDIUMConcrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block alias route, allowing an authenticated editor to disclose and force-delete arbitrary blocksEPSS 0.4%CVE-2026-81915MEDIUMIn Concrete CMS below 9.5.3, Page Type update omits object-level authorizationEPSS 0.4%CVE-2026-68529LOWConcrete CMS 9.0.0 through 9.5.2 us missing authorization in the Express entries advanced-search dashboard action allowing a low-privileged user to read other entities' Express entriesEPSS 0.4%CVE-2025-8573LOWConcrete CMS 9 through 9.4.2 is vulnerable to Stored XSS from Home Folder on Members Dashboard pageEPSS 0.4%CVE-2026-81898HIGHConcrete CMS below version 9.5.3 is vulnerable to Stored XSS via country-less Address attribute in Express association viewsEPSS 0.4%CVE-2024-7394MEDIUMConcrete CMS version 9.0.0 through 9.3.2 and below 8.5.18 - Stored XSS in getAttributeSetName()EPSS 0.4%CVE-2026-81910MEDIUMConcrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style ValuesEPSS 0.4%CVE-2024-1245LOWConcrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributesEPSS 0.4%CVE-2024-7512MEDIUMConcrete CMS Stored XSS in Board instancesEPSS 0.4%CVE-2026-81908MEDIUMMissing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows Authenticated Users to Enumerate All GroupsEPSS 0.4%CVE-2026-68533LOWMissing Authorization in Concrete CMS versions below 9.5.3 Conversation File Upload Allows File Import Without the Add Message Attachments PermissionEPSS 0.4%CVE-2026-7888HIGHConcrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction.EPSS 0.4%CVE-2026-81901HIGHConcrete CMS 9.2.0 to 9.5.2 is vulnerable to stored XSS due to missing authorization in the `PUT /pages/{cID}` endpointEPSS 0.4%