Vulnerability index

Browse CVEs

107 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-8435 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion(). The Concrete CM… Concrete Cms 9.5.1+ Fix from $1,6002026-05-21 HIGH 8.8 CVE-2026-8413 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design. The Concrete CMS secu… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8414 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate. The Concrete CMS secur… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8415 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder. The Concre… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8416 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id). The Concr… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8427 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id). The Co… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8432 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star(). The Concrete CMS security… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8433 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan(). The Concrete CMS securi… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8434 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple(). The Concrete CM… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8409 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete.  The The Concrete CMS secu… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8410 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete.  The The Concrete CMS… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8411 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete. The Concrete CMS secu… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8412 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache. The Concrete CMS secu… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 MEDIUM 5.4 CVE-2026-8245 Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection. Concrete\Core\Legacy\Pagination builds… Concrete Cms 9.5.1+ Fix from $1,6002026-05-21 MEDIUM 5.3 CVE-2026-8239 Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/get_rating' endpoint confirms existence and returns rating score… Concrete Cms 9.5.1+ Fix from $1,6002026-05-21 MEDIUM 5.3 CVE-2026-8240 Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure across every page with a configured summary template, revealin… Concrete Cms 9.5.1+ Fix from $1,6002026-05-21 MEDIUM 5.3 CVE-2026-8337 Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in such a way that both public an… Concrete Cms 9.5.1+ Fix from $1,6002026-05-21 MEDIUM 6.4 CVE-2026-7887 For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status. A user with uIsActive=0 (suspended, banned, terminate… Concrete Cms 9.5.1+ Fix from $1,6002026-05-21 MEDIUM 6.4 CVE-2026-7890 In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation enabli… Concrete Cms 9.5.1+ Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-8139 Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updateCollectionAliasExternal bypasses being sanitized… Concrete Cms after 9.5.0 Fix from $1,6002026-05-21 MEDIUM 5.3 CVE-2026-8237 Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations/message_detail` endpoint returns the full content of any convers… Concrete Cms 9.5.1+ Fix from $1,6002026-05-21 MEDIUM 5.3 CVE-2026-8238 Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/message_page' endpoint returns the full content of any conversat… Concrete Cms 9.5.1+ Fix from $1,6002026-05-21 MEDIUM 5.3 CVE-2026-7879 In Concrete CMS 9.5.0 and below,  the submit_password() method in concrete/controllers/single_page/download_file.php allows unauthorized file access … Concrete Cms 9.5.1+ Fix from $1,6002026-05-21 HIGH 8.8 CVE-2026-8421 Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/single_page/dashboard/extend/insta… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8426 Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/prepare_remote_upgrade/<remoteMPID… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8428 Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update')) but the corresponding do_update(… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8350 Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to privilege escalation to Adminis… Concrete Cms after 9.5.0 Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8417 Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/do_update/<pkgHandle>. The do_upda… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 MEDIUM 6.5 CVE-2026-8140 Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/install/download/<remoteId>. The download… Concrete Cms after 9.5.0 Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-8203 Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validate or sanitize $height. Any user with editor privi… Concrete Cms after 9.5.0 Fix from $1,6002026-05-21