Exposição de Concrete CMS

CMS
142
score de exposição
4.180
sites usam
0
em exploração
1
críticos
Análise Vexday

Com 74 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o Concrete CMS apresenta taxa de exploração abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. O dado mais relevante para atenção é o volume recente: 46 vulnerabilidades surgiram nos últimos 90 dias, sugerindo um ciclo ativo de descoberta e divulgação que demanda acompanhamento contínuo. O tipo de falha mais comum é CWE-352 (Cross-Site Request Forgery), padrão que aponta para fragilidades recorrentes na validação de requisições e que historicamente exige correções consistentes em múltiplos pontos da aplicação. A CVE mais perigosa atualmente, CVE-2024-1247, possui EPSS de 0,0124, refletindo probabilidade ainda baixa de exploração em larga escala, mas sua presença junto à única vulnerabilidade crítica do conjunto recomenda priorização nas equipes de patch management.

CVEs

139 resultados
CVE-2026-8433LOWConcrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan()EPSS 0.2%CVE-2026-8434LOWConcrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple()EPSS 0.2%CVE-2026-81912MEDIUMConcrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups featureEPSS 0.2%CVE-2025-3153MEDIUMConcrete CMS version 9 below 9.4.0RC2 and versions below 8.5.20 - CSRF and XSS in Concrete CMS Custom Address attributeEPSS 0.2%CVE-2026-8417HIGHConcrete CMS 9.5.0 and below is vulnerable to CSRF in do_update() in the package update controllerEPSS 0.2%CVE-2026-8428HIGHCSRF token is not validated in the core CMS update controller for Concrete CMS 9.5.0 and belowEPSS 0.2%CVE-2026-81920LOWConcrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Dashboard SEO Excluded Words Reset EndpointEPSS 0.2%CVE-2026-7882LOWConcrete CMS 9.5.0 and below is vulnerable to CSRF via the DeleteFile controllerEPSS 0.2%CVE-2026-8435LOWConcrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion()EPSS 0.2%CVE-2026-81897HIGHConcrete CMS below version 9.5.3 is vulnerable to Stored XSS via Express form Text control save_controlEPSS 0.2%CVE-2026-8140HIGHConcrete CMS 9.5.0 and below is vulnerable to CSRF on download() in the package install controllerEPSS 0.2%CVE-2026-18116HIGHConcrete CMS 8.3.0 to 9.5.2 is vulnerable to Stored XSS in Calendar Event Name via Workflow Approval NotificationsEPSS 0.2%CVE-2026-8340LOWConcrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersionEPSS 0.1%CVE-2026-81919LOWConcrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Block Arrangement EndpointEPSS 0.1%CVE-2026-10721HIGHConcrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and Search componentsEPSS 0.1%CVE-2026-18117HIGHConcrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Custom Page Alias NameEPSS 0.1%CVE-2026-81907MEDIUMConcrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) vin Express delete_entries allowing mass deletion of all entity recordsEPSS 0.1%CVE-2026-18425LOWIDOR in Concrete CMS 9.0.0 through 9.5.2 dashboard sitemap reorder (SitemapUpdate::updateDisplayOrder) allows an authenticated sitemap user to reorder arbitrary pagesEPSS 0.1%CVE-2026-68526MEDIUMConcrete CMS before 9.5.3 is vulnerable to CSRF in the Calendar event duplicate dialog controllerEPSS 0.1%