Vulnerabilidades en Concrete CMS

139 resultados
Análisis Vexday

Com 74 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o Concrete CMS apresenta taxa de exploração abaixo da média geral do catálogo, o que sugere menor pressão imediata de ataques oportunistas. No entanto, chama atenção o volume expressivo de 46 vulnerabilidades surgidas nos últimos 90 dias, indicando aceleração recente no ritmo de descoberta de falhas. O tipo de falha mais comum é CWE-352 (Cross-Site Request Forgery), padrão que tende a refletir deficiências estruturais na validação de requisições e merece atenção no processo de revisão de código. A CVE mais perigosa atualmente rastreada, CVE-2024-1247, possui EPSS de 0,0124, sinalizando probabilidade baixa de exploração em curto prazo, mas deve ser monitorada, especialmente diante do único CVE de severidade crítica presente no conjunto.

CVE-2024-1245LOWConcrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributesEPSS 0.4%CVE-2024-7512MEDIUMConcrete CMS Stored XSS in Board instancesEPSS 0.4%CVE-2026-81906MEDIUM[UNREVIEWED] OAuth Callback Login Bypasses Deactivated-Account ChecksEPSS 0.4%CVE-2024-2753LOWConcrete CMS version 9 below 9.2.8 and below 8.5.16 is vulnerable to stored XSS on the calendar color settings screenEPSS 0.4%CVE-2024-3178LOWConcrete CMS versions 9 below 9.2.8 and versions below 8.5.16 are vulnerable to Cross-site Scripting (XSS) in the Advanced File Search FilterEPSS 0.4%CVE-2024-3181LOWConcrete CMS version 9 prior to 9.2.8 and previous versions prior to 8.5.16 are vulnerable to Stored XSS in the Search Field.EPSS 0.4%CVE-2024-3180LOWConcrete CMS version 9 below 9.2.8 and previous versions below 8.5.16 is vulnerable to Stored XSS in blocks of type fileEPSS 0.4%CVE-2024-3179LOWConcrete CMS version 9 before 9.2.8 and previous versions before 8.5.16 are vulnerable to Stored XSS in the Custom Class pageEPSS 0.4%CVE-2026-18111HIGHConcrete CMS below 9.5.4 allows privilege escalation because adding users and assigning groups do not require additional identity verificationEPSS 0.3%CVE-2026-68535MEDIUMConcrete CMS 9.2.0 to 9.5.2 is vulnerable to Missing authorization in the Concrete CMS Area REST API block-create path letting an editor reference files outside their file-manager permissionsEPSS 0.3%CVE-2025-0660MEDIUMStored XSS in Folder Function by Rogue AdminEPSS 0.3%CVE-2025-8571MEDIUMConcrete CMS 9 through 9.4.2 and below 8.5.21 is vulnerable to Reflected Cross-Site Scripting (XSS) in Conversation Messages Dashboard PageEPSS 0.3%CVE-2026-18119HIGHConcrete CMS below 9.5.3 is vulnerable to Stored XSS via unsanitized inline block custom style valuesEPSS 0.3%CVE-2026-81899HIGHConcrete CMS 9.0 to 9.5.2 is vulnerable to Stored XSS via group folder name on the Members > Groups dashboardEPSS 0.3%CVE-2024-2179LOWConcrete CMS version 9 before 9.2.7 is vulnerable to Stored XSS via the Name field of a Group typeEPSS 0.3%CVE-2026-18117HIGHConcrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Custom Page Alias NameEPSS 0.3%CVE-2026-81895HIGHConcrete CMS 9.5.2 and below is vulnerable to Stored SQL Injection in Concrete CMS Document Library Block via `fsID[]` in `setMode=any`EPSS 0.3%CVE-2024-4353MEDIUMStored XSS in Generate Board Name Input FieldEPSS 0.3%CVE-2026-8350HIGHConcrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to privilege escalation to Administrative GroupEPSS 0.3%CVE-2026-87028MEDIUMCross-Board IDOR in the Board Custom Slot Preview in Concrete CMS 9.0.0 through 9.5.3 Discloses Restricted Page Summary FieldsEPSS 0.3%