Vulnerability index

Browse CVEs

107 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Concrete Cms MEDIUM 5.3
CVE-2026-8204

Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend Dialog which can allow cross-calendar data disclosu…

Fix: 9.5.1+
Fix from $1,600 2026-05-21
Concrete Cms MEDIUM 5.3
CVE-2026-8205

Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calendar Block since action_get_events does not check canView on the calend…

Fix: after 9.5.0
Fix from $1,600 2026-05-21
Concrete Cms HIGH 7.2
CVE-2026-8134

Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page ty…

Fix: after 9.5.0
Fix from $1,950 2026-05-21
Concrete Cms HIGH 7.2
CVE-2026-8135

Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the ExpressEntryList block controll…

Fix: after 9.5.0
Fix from $1,950 2026-05-21
Concrete Cms MEDIUM 5.3
CVE-2026-6826

Concrete CMS 9.5.0 and below  is vulnerable to unauthenticated file usage disclosure via missing permission check in the usage controller.  Any unaut…

Fix: 9.5.1+
Fix from $1,600 2026-05-21
Concrete Cms MEDIUM 6.5
CVE-2026-30662

ConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. The 'download' method in 'concrete/controllers/bac…

No fix yet
Fix from $1,600 2026-03-24
Concrete Cms MEDIUM 6.8
CVE-2026-2994

Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configuration via group_id parameter…

Fix: 9.4.8+
Fix from $1,600 2026-03-04
Concrete Cms HIGH 7.2
CVE-2026-3452

Concrete CMS below version 9.4.8 is vulnerable to Remote Code Execution by stored PHP object injection into the Express Entry List block via the colu…

Fix: 9.4.8+
Fix from $1,950 2026-03-04
Concrete Cms MEDIUM 6.5
CVE-2025-3153

Concrete CMS version 9 below 9.4.0RC2 and versions below 8.5.20 are vulnerable to CSRF and XSS in the Concrete CMS Address attribute because addresse…

Fix: 8.5.20 / 9.4.0+
Fix from $1,600 2025-04-03
Concrete Cms MEDIUM 5.4
CVE-2024-7398

Concrete CMS versions 9 through 9.3.3 and versions below 8.5.19 are vulnerable to stored XSS in the calendar event addition feature because the calen…

Fix: 8.5.19 / 9.3.3+
Fix from $1,600 2024-09-25
Concrete Cms CRITICAL 9.8
CVE-2023-48648

Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creatio…

Fix: 8.5.13 / 9.2.2+
Fix from $2,300 2023-11-17
Concrete Cms MEDIUM 5.4
CVE-2023-48649

Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows stored XSS on the Admin page via an uploaded file name.

Fix: 8.5.13 / 9.2.2+
Fix from $1,600 2023-11-17
Concrete Cms MEDIUM 5.4
CVE-2023-44763

Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cross-Site Scripting (XSS). NOTE:…

No fix yet
Fix from $1,600 2023-10-10
Concrete Cms MEDIUM 5.4
CVE-2023-44761

Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS versions affected to 8.5.13 and below, and 9.0.0 through 9.2.1 allow a local atta…

No fix yet
Fix from $1,600 2023-10-06
Concrete Cms MEDIUM 5.4
CVE-2023-44762

A Cross Site Scripting (XSS) vulnerability in Concrete CMS from versions 9.2.0 to 9.2.2 allows an attacker to execute arbitrary code via a crafted sc…

No fix yet
Fix from $1,600 2023-10-06
Concrete Cms MEDIUM 5.4
CVE-2023-44764

A Cross Site Scripting (XSS) vulnerability in Concrete CMS before 9.2.3 exists via the Name parameter during installation (aka Site of Installation o…

No fix yet
Fix from $1,600 2023-10-06
Concrete Cms MEDIUM 5.4
CVE-2023-44765

A Cross Site Scripting (XSS) vulnerability in Concrete CMS versions 8.5.12 and below, and 9.0 through 9.2.1 allows an attacker to execute arbitrary c…

No fix yet
Fix from $1,600 2023-10-06
Concrete Cms MEDIUM 6.1
CVE-2023-28475

Concrete CMS (previously concrete5) versions 8.5.12 and below, and versions 9.0 through 9.1.3 is vulnerable to Reflected XSS on the Reply form becaus…

Fix: 9.2.0+
Fix from $1,600 2023-04-28
Concrete Cms MEDIUM 5.4
CVE-2023-28471

Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS via a container name.

Fix: 9.2.0+
Fix from $1,600 2023-04-28
Concrete Cms MEDIUM 5.4
CVE-2023-28474

Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Saved Presets on search.

Fix: 9.2.0+
Fix from $1,600 2023-04-28
Concrete Cms MEDIUM 5.4
CVE-2023-28476

Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Tags on uploaded files.

Fix: 9.2.0+
Fix from $1,600 2023-04-28
Concrete Cms MEDIUM 5.4
CVE-2023-28477

Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to stored XSS on API Integrations via the name par…

Fix: 9.2.0+
Fix from $1,600 2023-04-28
Concrete Cms MEDIUM 5.4
CVE-2023-28819

Concrete CMS (previously concrete5) versions 8.5.12 and below, 9.0.0 through 9.0.2 is vulnerable to Stored XSS in uploaded file and folder names.

Fix: 9.1.0+
Fix from $1,600 2023-04-28
Concrete Cms MEDIUM 5.4
CVE-2023-28820

Concrete CMS (previously concrete5) before 9.1 is vulnerable to stored XSS in RSS Displayer via the href attribute because the link element input was…

Fix: 9.1.0+
Fix from $1,600 2023-04-28
Concrete Cms MEDIUM 5.3
CVE-2023-28472

Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 does not have Secure and HTTP only attributes set for ccmPoll co…

Fix: 9.2.0+
Fix from $1,600 2023-04-28
Concrete Cms MEDIUM 5.3
CVE-2023-28821

Concrete CMS (previously concrete5) before 9.1 did not have a rate limit for password resets.

Fix: 9.1.0+
Fix from $1,600 2023-04-28
Concrete Cms MEDIUM 6.1
CVE-2022-43556

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XSS in the text input field since the result dashboard pa…

Fix: 8.5.10+
Fix from $1,600 2022-12-05
Concrete Cms MEDIUM 6.3
CVE-2022-43690

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 did not use strict comparison for the legacy_salt so that limited authenti…

Fix: 8.5.10+
Fix from $1,600 2022-11-14
Concrete Cms MEDIUM 5.3
CVE-2022-43689

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XXE based DNS requests leading to IP disclosure.

Fix: 8.5.10+
Fix from $1,600 2022-11-14
Concrete Cms MEDIUM 5.3
CVE-2022-43691

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 inadvertently disclose server-side sensitive information (secrets in envir…

Fix: 8.5.10+
Fix from $1,600 2022-11-14