Vulnerabilidades em Concrete CMS

139 resultados
Análise Vexday

Com 74 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o Concrete CMS apresenta taxa de exploração abaixo da média geral do catálogo, o que sugere menor pressão imediata de ataques oportunistas. No entanto, chama atenção o volume expressivo de 46 vulnerabilidades surgidas nos últimos 90 dias, indicando aceleração recente no ritmo de descoberta de falhas. O tipo de falha mais comum é CWE-352 (Cross-Site Request Forgery), padrão que tende a refletir deficiências estruturais na validação de requisições e merece atenção no processo de revisão de código. A CVE mais perigosa atualmente rastreada, CVE-2024-1247, possui EPSS de 0,0124, sinalizando probabilidade baixa de exploração em curto prazo, mas deve ser monitorada, especialmente diante do único CVE de severidade crítica presente no conjunto.

CVE-2026-3242MEDIUMConcrete CMS below 9.4.8 is vulnerable to Stored XSS in the Switch Language blockEPSS 0.2%CVE-2026-81916MEDIUMIncorrect Authorization in the Concrete CMS Express Entries Dashboard below version 9.5.3 Allows Entry Creation in an Unauthorized ObjectEPSS 0.2%CVE-2026-8240MEDIUMConcrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure in Backend\SummaryTemplateEPSS 0.2%CVE-2026-3244MEDIUMConcrete CMS below version 9.4.8 is vulnerable to Stored XSS in Search Results via Page NamesEPSS 0.2%CVE-2026-8239MEDIUMConcrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/get_rating'EPSS 0.2%CVE-2026-8337MEDIUMConcrete CMS 9.5.0 and below is vulnerable to IDOR in surveys when sites are running concurrent public surveys and private surveysEPSS 0.2%CVE-2026-85387LOWConcrete CMS before 9.5.4 allows a deactivated user to retain OAuth-authenticated REST API accessEPSS 0.2%CVE-2026-68526MEDIUMConcrete CMS before 9.5.3 is vulnerable to CSRF in the Calendar event duplicate dialog controllerEPSS 0.2%CVE-2026-81926LOWConcrete CMS 9.4.0 through 9.5.2 is vulnerable to Cross-site scripting in the location panel duplicate-path confirmation dialogEPSS 0.2%CVE-2026-8197HIGHConcrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration nameEPSS 0.2%CVE-2026-8327MEDIUMConcrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass.EPSS 0.2%CVE-2026-81918MEDIUMConcrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display blockEPSS 0.2%CVE-2026-81922LOW"In Concrete CMS below 9.5.3, there is Missing authorization in the sitemap page reorder allowing low-privilege users to reorder arbitrary pages "EPSS 0.2%CVE-2026-81923LOWConcrete CMS below 9.5.3 is missing authorization in the SEO Bulk Update Meta Tags editorEPSS 0.2%CVE-2026-81912MEDIUMConcrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups featureEPSS 0.2%CVE-2026-7887LOWFor Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account StatusEPSS 0.2%CVE-2026-8426HIGHConcrete CMS 9.5.0 and below is vulnerable to CSRF on prepare_remote_upgrade() leading to one-request RCE via package overwriteEPSS 0.2%CVE-2026-8421HIGHConcrete CMS 9.5.0 and below is vulnerable to CSRF on install_package() with conditional token bypass leading to RCEEPSS 0.2%CVE-2026-81917MEDIUMConcrete CMS below 9.5.3 is vulnerable to Stored XSS in the Document Library block file description and tagsEPSS 0.2%CVE-2026-81927LOWConcrete CMS before 9.5.3 is vulnerable to Stored XSS via SVG upload in "Reject" sanitization modeEPSS 0.2%