Exposición de Concrete CMS

CMS
142
score de exposición
4180
sitios usan
0
en explotación
1
críticos
Análisis Vexday

Com 74 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o Concrete CMS apresenta taxa de exploração abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. O dado mais relevante para atenção é o volume recente: 46 vulnerabilidades surgiram nos últimos 90 dias, sugerindo um ciclo ativo de descoberta e divulgação que demanda acompanhamento contínuo. O tipo de falha mais comum é CWE-352 (Cross-Site Request Forgery), padrão que aponta para fragilidades recorrentes na validação de requisições e que historicamente exige correções consistentes em múltiplos pontos da aplicação. A CVE mais perigosa atualmente, CVE-2024-1247, possui EPSS de 0,0124, refletindo probabilidade ainda baixa de exploração em larga escala, mas sua presença junto à única vulnerabilidade crítica do conjunto recomenda priorização nas equipes de patch management.

CVEs

139 resultados
CVE-2026-68531LOWConcrete CMS below 9.5.3 is vulnerable to Authenticated Denial of Service via Unescaped SQL LIKE Wildcards in Keyword SearchEPSS 0.5%CVE-2026-81904MEDIUMConcrete CMS before 9.5.3 is vulnerable to Missing Authorization in Stack/Container Sub-Block Asset RegistrationEPSS 0.5%CVE-2024-1246LOWConcrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import FeatureEPSS 0.5%CVE-2026-18422LOWConcrete CMS below 9.5.3 Multilingual Page Assign Action Lacks Destination Authorization and CSRF Token ValidationEPSS 0.4%CVE-2026-81909MEDIUMConcrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block alias route, allowing an authenticated editor to disclose and force-delete arbitrary blocksEPSS 0.4%CVE-2024-8661MEDIUMConcrete CMS version 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" blockEPSS 0.4%CVE-2026-68529LOWConcrete CMS 9.0.0 through 9.5.2 us missing authorization in the Express entries advanced-search dashboard action allowing a low-privileged user to read other entities' Express entriesEPSS 0.4%CVE-2025-8573LOWConcrete CMS 9 through 9.4.2 is vulnerable to Stored XSS from Home Folder on Members Dashboard pageEPSS 0.4%CVE-2026-81898HIGHConcrete CMS below version 9.5.3 is vulnerable to Stored XSS via country-less Address attribute in Express association viewsEPSS 0.4%CVE-2024-7394MEDIUMConcrete CMS version 9.0.0 through 9.3.2 and below 8.5.18 - Stored XSS in getAttributeSetName()EPSS 0.4%CVE-2026-81910MEDIUMConcrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style ValuesEPSS 0.4%CVE-2024-1245LOWConcrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributesEPSS 0.4%CVE-2024-7512MEDIUMConcrete CMS Stored XSS in Board instancesEPSS 0.4%CVE-2026-81908MEDIUMMissing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows Authenticated Users to Enumerate All GroupsEPSS 0.4%CVE-2026-68533LOWMissing Authorization in Concrete CMS versions below 9.5.3 Conversation File Upload Allows File Import Without the Add Message Attachments PermissionEPSS 0.4%CVE-2026-7888HIGHConcrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction.EPSS 0.4%CVE-2026-81901HIGHConcrete CMS 9.2.0 to 9.5.2 is vulnerable to stored XSS due to missing authorization in the `PUT /pages/{cID}` endpointEPSS 0.4%CVE-2026-68528MEDIUMConcrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Block via Unescaped Remote Feed Item titleEPSS 0.4%CVE-2026-87028MEDIUMCross-Board IDOR in the Board Custom Slot Preview in Concrete CMS 9.0.0 through 9.5.3 Discloses Restricted Page Summary FieldsEPSS 0.4%CVE-2024-2753LOWConcrete CMS version 9 below 9.2.8 and below 8.5.16 is vulnerable to stored XSS on the calendar color settings screenEPSS 0.4%