Vulnerabilidades em Concrete CMS

139 resultados
Análise Vexday

Com 74 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o Concrete CMS apresenta taxa de exploração abaixo da média geral do catálogo, o que sugere menor pressão imediata de ataques oportunistas. No entanto, chama atenção o volume expressivo de 46 vulnerabilidades surgidas nos últimos 90 dias, indicando aceleração recente no ritmo de descoberta de falhas. O tipo de falha mais comum é CWE-352 (Cross-Site Request Forgery), padrão que tende a refletir deficiências estruturais na validação de requisições e merece atenção no processo de revisão de código. A CVE mais perigosa atualmente rastreada, CVE-2024-1247, possui EPSS de 0,0124, sinalizando probabilidade baixa de exploração em curto prazo, mas deve ser monitorada, especialmente diante do único CVE de severidade crítica presente no conjunto.

CVE-2026-81905MEDIUMConcrete CMS below 9.5.3 does not enforce validation-hash type on redemption, allowing a hash issued for one purpose to be redeemed for another.EPSS 0.2%CVE-2026-18424LOWConcrete CMS 9.0.0 to 9.5.2 is vulnerable to SSRF protection bypass in remote file import when multiple URLs share a host but use different portsEPSS 0.2%CVE-2026-68528MEDIUMConcrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Block via Unescaped Remote Feed Item titleEPSS 0.2%CVE-2026-18122MEDIUMConcrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing AuthorizationEPSS 0.2%CVE-2026-81908MEDIUMMissing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows Authenticated Users to Enumerate All GroupsEPSS 0.2%CVE-2026-8347LOWConcrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialogEPSS 0.2%CVE-2026-7879MEDIUMConcrete CMS 9.5.0 and below is vulnerable to File Download Authorization Bypass in submit_password()EPSS 0.2%CVE-2026-85386HIGHConcrete CMS before 9.5.4 stored is vulneratble to cross-site scripting via unauthenticated XML/XSLT file upload in the Form BlockEPSS 0.2%CVE-2026-3240MEDIUMConcrete CMS below 9.4.8 is vulnerable to Stored XSS via Legacy formEPSS 0.2%CVE-2026-8205MEDIUMConcrete CMS 9.5.0 and below is vulnerable to authorization bypass in Calendar Block since action_get_events does not check canView on the calendarEPSS 0.2%CVE-2026-8204MEDIUMConcrete CMS 9.5.0 and below is vulnerable to Authorization Bypass in the Calendar Event Frontend DialogEPSS 0.2%CVE-2026-68532LOWConcrete CMS 9.0.0 to 9.5.2 is vunerable to CSRF in Concrete CMS Group Type Deletion Dashboard ActionEPSS 0.2%CVE-2026-81907MEDIUMConcrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) vin Express delete_entries allowing mass deletion of all entity recordsEPSS 0.2%CVE-2026-81903HIGHConcrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS via Page Container iconEPSS 0.2%CVE-2026-2994LOWConcrete CMS below 9.4.8 is vulnerable to CSRF by a Rogue Admin using the Anti-Spam Allowlist GroupEPSS 0.2%CVE-2026-3241MEDIUMConcrete CMS below version 9.4.8 is vulnerable to a stored cross-site scripting (XSS) in the "Legacy Form" block.EPSS 0.2%CVE-2026-18426LOWConcrete CMS 9.0.0 to 9.5.2 Express Form block missing authorization allows an authenticated editor to modify Express Forms they cannot editEPSS 0.2%CVE-2026-7881MEDIUMConcrete CMS 9.5.0 and below is vulnerable to IDOR in the Express Entry Detail blockEPSS 0.2%CVE-2026-81925LOWConcrete CMS below 9.5.3 is vulnerable to Reflected Cross-Site Scripting (XSS) via Conversation Custom Date FormatEPSS 0.2%CVE-2026-8238MEDIUMConcrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/message_page' allowing unauthenticated read of any conversation messageEPSS 0.2%