concretecms
64 known vulnerabilities affecting concretecms products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-8327 | Low | 0.2% | 4.3 | Concrete CMS below 9.5.0 and below is vulnerable to password change without reau… | |
| CVE-2026-81903 | Low | 0.2% | 5.4 | Concrete CMS versions 9.0.0 to 9.5.2 stored the Page Container icon value submit… | |
| CVE-2026-7887 | Low | 0.2% | 6.4 | For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses … | |
| CVE-2026-81919 | Low | 0.2% | 4.3 | Concrete CMS below 9.5.3 did not validate an anti-CSRF token on the block-arrang… | |
| CVE-2026-7890 | Low | 0.2% | 6.4 | In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from… | |
| CVE-2026-8139 | Low | 0.2% | 5.4 | Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page … | |
| CVE-2026-8353 | Low | 0.1% | 4.8 | Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in t… | |
| CVE-2026-81900 | Low | 0.1% | 6.1 | Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored widt… | |
| CVE-2026-8245 | Low | 0.1% | 5.4 | Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination… | |
| CVE-2026-8203 | Low | 0.1% | 5.4 | Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The control… | |
| CVE-2026-8140 | Low | 0.1% | 6.5 | Concrete CMS 9.5.0 and below does not validate a CSRF token before processing re… | |
| CVE-2026-7882 | Low | 0.1% | 4.3 | Concrete CMS 9.5.0 and below is vulnerable to unauthorized file deletion due to… | |
| CVE-2026-8435 | Low | 0.1% | 6.5 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a… | |
| CVE-2026-8340 | Low | 0.1% | 4.3 | Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVers… |
← Prev Page 2 of 2