Vulnerability index

Browse CVEs

107 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Concrete Cms MEDIUM 6.5
CVE-2026-8435

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion(). The Concrete CM…

Fix: 9.5.1+
Fix from $1,600 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8413

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design. The Concrete CMS secu…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8414

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate. The Concrete CMS secur…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8415

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder. The Concre…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8416

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id). The Concr…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8427

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id). The Co…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8432

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star(). The Concrete CMS security…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8433

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan(). The Concrete CMS securi…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8434

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple(). The Concrete CM…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8409

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete.  The The Concrete CMS secu…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8410

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete.  The The Concrete CMS…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8411

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete. The Concrete CMS secu…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8412

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache. The Concrete CMS secu…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms MEDIUM 5.4
CVE-2026-8245

Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection. Concrete\Core\Legacy\Pagination builds…

Fix: 9.5.1+
Fix from $1,600 2026-05-21
Concrete Cms MEDIUM 5.3
CVE-2026-8239

Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/get_rating' endpoint confirms existence and returns rating score…

Fix: 9.5.1+
Fix from $1,600 2026-05-21
Concrete Cms MEDIUM 5.3
CVE-2026-8240

Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure across every page with a configured summary template, revealin…

Fix: 9.5.1+
Fix from $1,600 2026-05-21
Concrete Cms MEDIUM 5.3
CVE-2026-8337

Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in such a way that both public an…

Fix: 9.5.1+
Fix from $1,600 2026-05-21
Concrete Cms MEDIUM 6.4
CVE-2026-7887

For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status. A user with uIsActive=0 (suspended, banned, terminate…

Fix: 9.5.1+
Fix from $1,600 2026-05-21
Concrete Cms MEDIUM 6.4
CVE-2026-7890

In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation enabli…

Fix: 9.5.1+
Fix from $1,600 2026-05-21
Concrete Cms MEDIUM 5.4
CVE-2026-8139

Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updateCollectionAliasExternal bypasses being sanitized…

Fix: after 9.5.0
Fix from $1,600 2026-05-21
Concrete Cms MEDIUM 5.3
CVE-2026-8237

Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations/message_detail` endpoint returns the full content of any convers…

Fix: 9.5.1+
Fix from $1,600 2026-05-21
Concrete Cms MEDIUM 5.3
CVE-2026-8238

Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/message_page' endpoint returns the full content of any conversat…

Fix: 9.5.1+
Fix from $1,600 2026-05-21
Concrete Cms MEDIUM 5.3
CVE-2026-7879

In Concrete CMS 9.5.0 and below,  the submit_password() method in concrete/controllers/single_page/download_file.php allows unauthorized file access …

Fix: 9.5.1+
Fix from $1,600 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8421

Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/single_page/dashboard/extend/insta…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8426

Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/prepare_remote_upgrade/<remoteMPID…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8428

Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update')) but the corresponding do_update(…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8350

Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to privilege escalation to Adminis…

Fix: after 9.5.0
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8417

Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/do_update/<pkgHandle>. The do_upda…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms MEDIUM 6.5
CVE-2026-8140

Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/install/download/<remoteId>. The download…

Fix: after 9.5.0
Fix from $1,600 2026-05-21
Concrete Cms MEDIUM 5.4
CVE-2026-8203

Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validate or sanitize $height. Any user with editor privi…

Fix: after 9.5.0
Fix from $1,600 2026-05-21