Vulnerabilidades em Concrete CMS

139 resultados
Análise Vexday

Com 74 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o Concrete CMS apresenta taxa de exploração abaixo da média geral do catálogo, o que sugere menor pressão imediata de ataques oportunistas. No entanto, chama atenção o volume expressivo de 46 vulnerabilidades surgidas nos últimos 90 dias, indicando aceleração recente no ritmo de descoberta de falhas. O tipo de falha mais comum é CWE-352 (Cross-Site Request Forgery), padrão que tende a refletir deficiências estruturais na validação de requisições e merece atenção no processo de revisão de código. A CVE mais perigosa atualmente rastreada, CVE-2024-1247, possui EPSS de 0,0124, sinalizando probabilidade baixa de exploração em curto prazo, mas deve ser monitorada, especialmente diante do único CVE de severidade crítica presente no conjunto.

CVE-2024-8660MEDIUMStored XSS in the "Top Navigator Bar" blockEPSS 0.3%CVE-2026-18121MEDIUMConcrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) in the Calendar block's frontend event dialog (/ccm/calendar/view_event/{bID}/{occurrence_id}).EPSS 0.3%CVE-2026-68530LOWConcrete CMS 9.0.0 through 9.5.2 is Missing Authorization on Board Instance Actions Allowed a Board Editor to Access and Delete Other Boards' InstancesEPSS 0.3%CVE-2026-7886LOWConcrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameterEPSS 0.3%CVE-2026-68531LOWConcrete CMS below 9.5.3 is vulnerable to Authenticated Denial of Service via Unescaped SQL LIKE Wildcards in Keyword SearchEPSS 0.3%CVE-2026-68533LOWMissing Authorization in Concrete CMS versions below 9.5.3 Conversation File Upload Allows File Import Without the Add Message Attachments PermissionEPSS 0.3%CVE-2026-18113HIGHConcrete CMS 9.0 to 9.5.2 is vulnerable to Stored XSS in the Top Navigation Bar Block via Dropdown Child Page NamesEPSS 0.3%CVE-2026-81904MEDIUMConcrete CMS before 9.5.3 is vulnerable to Missing Authorization in Stack/Container Sub-Block Asset RegistrationEPSS 0.3%CVE-2026-81901HIGHConcrete CMS 9.2.0 to 9.5.2 is vulnerable to stored XSS due to missing authorization in the `PUT /pages/{cID}` endpointEPSS 0.3%CVE-2026-68527MEDIUMConcrete CMS 8.3.0 through 9.5.2 is vulnerable to an authorization bypass through user-controlled key (cross-calendar IDOR) in the Calendar event edit dialogEPSS 0.3%CVE-2026-18421LOWConcrete CMS 9.0.0-9.5.2 Boards data source dashboard is missing an authorization check, allowing a low-privileged board editor to modify or delete configured data sources on boards they do not controlEPSS 0.3%CVE-2026-68529LOWConcrete CMS 9.0.0 through 9.5.2 us missing authorization in the Express entries advanced-search dashboard action allowing a low-privileged user to read other entities' Express entriesEPSS 0.3%CVE-2026-18120MEDIUMMissing Authorization in legacy Express entries search endpoint allows disclosure of Express entry dataEPSS 0.3%CVE-2026-18110HIGHConcrete CMS 9.0.0 through 9.5.2 is vulnerable to missing authorization in the user selector autocomplete endpoint (/ccm/system/user/autocomplete), allowing an unauthenticated attacker to retrieve the complete backend user directory — internal ID, usernameEPSS 0.3%CVE-2026-87031LOWMissing authorization in the REST API user creation endpoint in Concrete CMS 9.2.0 through 9.5.3 allows arbitrary account creationEPSS 0.3%CVE-2026-81909MEDIUMConcrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block alias route, allowing an authenticated editor to disclose and force-delete arbitrary blocksEPSS 0.3%CVE-2026-18115HIGHIn Concrete CMS 9.2.0 to 9.5.2, Missing Authorization in REST API Users update() and change_password Enables Account Takeover.EPSS 0.3%CVE-2026-81898HIGHConcrete CMS below version 9.5.3 is vulnerable to Stored XSS via country-less Address attribute in Express association viewsEPSS 0.3%CVE-2026-18423LOWConcrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs allowing an authenticated user with permission on one Express entity to delete or rename saved search presEPSS 0.2%CVE-2026-81910MEDIUMConcrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style ValuesEPSS 0.2%