Vulnerabilities in Concrete CMS

139 results
Vexday analysis

Com 74 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o Concrete CMS apresenta taxa de exploração abaixo da média geral do catálogo, o que sugere menor pressão imediata de ataques oportunistas. No entanto, chama atenção o volume expressivo de 46 vulnerabilidades surgidas nos últimos 90 dias, indicando aceleração recente no ritmo de descoberta de falhas. O tipo de falha mais comum é CWE-352 (Cross-Site Request Forgery), padrão que tende a refletir deficiências estruturais na validação de requisições e merece atenção no processo de revisão de código. A CVE mais perigosa atualmente rastreada, CVE-2024-1247, possui EPSS de 0,0124, sinalizando probabilidade baixa de exploração em curto prazo, mas deve ser monitorada, especialmente diante do único CVE de severidade crítica presente no conjunto.

CVE-2026-8411LOWConcrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/deleteEPSS 0.2%CVE-2026-8416LOWConcrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id)EPSS 0.2%CVE-2026-8415LOWConcrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorderEPSS 0.2%CVE-2026-8427LOWConcrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id)EPSS 0.2%CVE-2026-8432LOWConcrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star()EPSS 0.2%CVE-2026-8413LOWConcrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/designEPSS 0.2%CVE-2026-8428HIGHCSRF token is not validated in the core CMS update controller for Concrete CMS 9.5.0 and belowEPSS 0.2%CVE-2026-8417HIGHConcrete CMS 9.5.0 and below is vulnerable to CSRF in do_update() in the package update controllerEPSS 0.2%CVE-2026-81920LOWConcrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Dashboard SEO Excluded Words Reset EndpointEPSS 0.2%CVE-2026-7882LOWConcrete CMS 9.5.0 and below is vulnerable to CSRF via the DeleteFile controllerEPSS 0.2%CVE-2026-8435LOWConcrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion()EPSS 0.2%CVE-2025-3153MEDIUMConcrete CMS version 9 below 9.4.0RC2 and versions below 8.5.20 - CSRF and XSS in Concrete CMS Custom Address attributeEPSS 0.2%CVE-2026-81897HIGHConcrete CMS below version 9.5.3 is vulnerable to Stored XSS via Express form Text control save_controlEPSS 0.2%CVE-2026-8140HIGHConcrete CMS 9.5.0 and below is vulnerable to CSRF on download() in the package install controllerEPSS 0.2%CVE-2026-18116HIGHConcrete CMS 8.3.0 to 9.5.2 is vulnerable to Stored XSS in Calendar Event Name via Workflow Approval NotificationsEPSS 0.2%CVE-2026-81919LOWConcrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Block Arrangement EndpointEPSS 0.1%CVE-2026-8340LOWConcrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersionEPSS 0.1%CVE-2026-10721HIGHConcrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and Search componentsEPSS 0.1%CVE-2026-18425LOWIDOR in Concrete CMS 9.0.0 through 9.5.2 dashboard sitemap reorder (SitemapUpdate::updateDisplayOrder) allows an authenticated sitemap user to reorder arbitrary pagesEPSS 0.1%