Exposição de Concrete CMS

CMS
142
score de exposição
4.180
sites usam
0
em exploração
1
críticos
Análise Vexday

Com 74 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o Concrete CMS apresenta taxa de exploração abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. O dado mais relevante para atenção é o volume recente: 46 vulnerabilidades surgiram nos últimos 90 dias, sugerindo um ciclo ativo de descoberta e divulgação que demanda acompanhamento contínuo. O tipo de falha mais comum é CWE-352 (Cross-Site Request Forgery), padrão que aponta para fragilidades recorrentes na validação de requisições e que historicamente exige correções consistentes em múltiplos pontos da aplicação. A CVE mais perigosa atualmente, CVE-2024-1247, possui EPSS de 0,0124, refletindo probabilidade ainda baixa de exploração em larga escala, mas sua presença junto à única vulnerabilidade crítica do conjunto recomenda priorização nas equipes de patch management.

CVEs

139 resultados
CVE-2024-4353MEDIUMStored XSS in Generate Board Name Input FieldEPSS 0.3%CVE-2026-68532LOWConcrete CMS 9.0.0 to 9.5.2 is vunerable to CSRF in Concrete CMS Group Type Deletion Dashboard ActionEPSS 0.3%CVE-2026-81923LOWConcrete CMS below 9.5.3 is missing authorization in the SEO Bulk Update Meta Tags editorEPSS 0.3%CVE-2026-81922LOW"In Concrete CMS below 9.5.3, there is Missing authorization in the sitemap page reorder allowing low-privilege users to reorder arbitrary pages "EPSS 0.3%CVE-2026-8347LOWConcrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialogEPSS 0.3%CVE-2026-81913MEDIUMConcrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter.EPSS 0.3%CVE-2026-81915MEDIUMIn Concrete CMS below 9.5.3, Page Type update omits object-level authorizationEPSS 0.3%CVE-2024-8660MEDIUMStored XSS in the "Top Navigator Bar" blockEPSS 0.3%CVE-2026-18121MEDIUMConcrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) in the Calendar block's frontend event dialog (/ccm/calendar/view_event/{bID}/{occurrence_id}).EPSS 0.3%CVE-2026-18113HIGHConcrete CMS 9.0 to 9.5.2 is vulnerable to Stored XSS in the Top Navigation Bar Block via Dropdown Child Page NamesEPSS 0.3%CVE-2026-7887LOWFor Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account StatusEPSS 0.3%CVE-2026-7881MEDIUMConcrete CMS 9.5.0 and below is vulnerable to IDOR in the Express Entry Detail blockEPSS 0.3%CVE-2026-81925LOWConcrete CMS below 9.5.3 is vulnerable to Reflected Cross-Site Scripting (XSS) via Conversation Custom Date FormatEPSS 0.3%CVE-2026-18120MEDIUMMissing Authorization in legacy Express entries search endpoint allows disclosure of Express entry dataEPSS 0.3%CVE-2026-81916MEDIUMIncorrect Authorization in the Concrete CMS Express Entries Dashboard below version 9.5.3 Allows Entry Creation in an Unauthorized ObjectEPSS 0.3%CVE-2026-18421LOWConcrete CMS 9.0.0-9.5.2 Boards data source dashboard is missing an authorization check, allowing a low-privileged board editor to modify or delete configured data sources on boards they do not controlEPSS 0.3%CVE-2026-3244MEDIUMConcrete CMS below version 9.4.8 is vulnerable to Stored XSS in Search Results via Page NamesEPSS 0.3%CVE-2026-3240MEDIUMConcrete CMS below 9.4.8 is vulnerable to Stored XSS via Legacy formEPSS 0.3%CVE-2026-3241MEDIUMConcrete CMS below version 9.4.8 is vulnerable to a stored cross-site scripting (XSS) in the "Legacy Form" block.EPSS 0.3%CVE-2026-3242MEDIUMConcrete CMS below 9.4.8 is vulnerable to Stored XSS in the Switch Language blockEPSS 0.3%