VulnSea

concrete_cms vulnerabilities

CVEs whose affected-version data names the concrete_cms package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

69 CVEsRSS

CVE-2026-18113High· 7.5
1w ago

In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing them into the page, so a user who could create or rename pages could store a script through a child page name and hav…

In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing them into the page, so a user who could create or rename pages could store a script through a child page name and hav…

▾ TwilightConcrete CMS · Concrete CMSEPSS 0.29%via NVD
CVE-2026-81897Medium· 5.4⚖ disputed
1w ago

In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not validate the anti-CSRF token

In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not validate the anti-CSRF token. By causing an authenticated administrator to submit a forged cross-site request, a remote a…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.17%via NVD
CVE-2026-81896Medium· 5.4⚖ disputed
1w ago

Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Form block question labels when rendering them as column headers in the Dashboard Form Submissions report (concrete/single_pages/dashboard/reports/forms/legacy…

Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Form block question labels when rendering them as column headers in the Dashboard Form Submissions report (concrete/single_pages/dashboard/reports/forms/legacy…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-81895High· 7.2
1w ago

In Concrete CMS before 9.5.3, the Document Library block stored the file-set identifiers submitted through fsID[] without validating them as integers, and when the block was configured with setMode set to any it concatenated each stored …

In Concrete CMS before 9.5.3, the Document Library block stored the file-set identifiers submitted through fsID[] without validating them as integers, and when the block was configured with setMode set to any it concatenated each stored …

▾ Twilightconcretecms · concrete_cmsEPSS 0.51%via NVD
CVE-2026-81894Medium· 5.4⚖ disputed
1w ago

Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-image Caption field because the bundled Magnific Popup lightbox script (concrete/js/features/imagery/frontend.js) re-pa…

Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-image Caption field because the bundled Magnific Popup lightbox script (concrete/js/features/imagery/frontend.js) re-pa…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-18111High· 8.5
1w ago

Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image, and Image blocks and before Concrete 8.5.21 in the feature and Image blocks because the external link URL was insuf…

Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image, and Image blocks and before Concrete 8.5.21 in the feature and Image blocks because the external link URL was insuf…

▾ TwilightConcrete CMS · Concrete CMSEPSS 0.34%via NVD
CVE-2026-18110High· 7.5
1w ago

Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint (/ccm/system/user/autocomplete), which backs the "Preview as User" panel and other user-selector components

Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint (/ccm/system/user/autocomplete), which backs the "Preview as User" panel and other user-selector components. The endp…

▾ Twilightconcretecms · concrete_cmsEPSS 0.27%via NVD
CVE-2026-18116Medium· 6.1
1w ago

Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in the workflow approval and deletion notifications shown in the dashboard "Waiting For Me" block

Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in the workflow approval and deletion notifications shown in the dashboard "Waiting For Me" block. A registered user per…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.15%via NVD
CVE-2026-81900Medium· 6.1
1w ago

Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them into iframe HTML attributes without escaping or integer casting, resulting in stored cross-site scripting

Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them into iframe HTML attributes without escaping or integer casting, resulting in stored cross-site scripting. A user with e…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.26%via NVD
CVE-2026-18117High· 7.3
1w ago

Concrete CMS 9.0.0 through 9.5.3 is vulnerable to stored XSS via the custom page alias name (customAliasName) because the Edit Alias dialog applied only trim() to the submitted value and performed no input neutralization

Concrete CMS 9.0.0 through 9.5.3 is vulnerable to stored XSS via the custom page alias name (customAliasName) because the Edit Alias dialog applied only trim() to the submitted value and performed no input neutralization. An authenticate…

▾ TwilightConcrete CMS · Concrete CMSEPSS 0.31%via NVD
CVE-2026-81903Medium· 5.4
1w ago

Concrete CMS versions 9.0.0 to 9.5.2 stored the Page Container icon value submitted through the dashboard without validating it against the set of known container icons

Concrete CMS versions 9.0.0 to 9.5.2 stored the Page Container icon value submitted through the dashboard without validating it against the set of known container icons. The unvalidated value was later concatenated into the src attribute…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.32%via NVD
CVE-2026-81902High· 8.1
1w ago

Concrete CMS 9 through 9.5.2 did not validate a CSRF token in the orphaned block removal panel action (removeOrphanedBlocks)

Concrete CMS 9 through 9.5.2 did not validate a CSRF token in the orphaned block removal panel action (removeOrphanedBlocks). A remote attacker could craft a request that, when loaded by an authenticated user holding edit permission on t…

▾ Twilightconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-81901High· 8.7
1w ago

In Concrete CMS 9.2.0 through 9.5.2, the REST API page update endpoint (PUT /ccm/api/1.0/pages/{cID}) did not enforce page-property, page-template, or page-type authorization

In Concrete CMS 9.2.0 through 9.5.2, the REST API page update endpoint (PUT /ccm/api/1.0/pages/{cID}) did not enforce page-property, page-template, or page-type authorization. A user granted only content-editing rights on a page could th…

▾ Twilightconcretecms · concrete_cmsEPSS 0.38%via NVD
CVE-2026-18119Critical· 9.0⚖ disputed
1w ago

Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page CSS via a DOM sink, permitting stored cross-site scripting

Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page CSS via a DOM sink, permitting stored cross-site scripting. An editor-level user could execute script in an administra…

▾ Midnightconcretecms · concrete_cmsEPSS 0.31%via NVD
CVE-2026-81907High· 7.1
2w ago

Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function (POST /index.php/dashboard/system/express/entities/delete_entries) because the controller records but does not enforc…

Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function (POST /index.php/dashboard/system/express/entities/delete_entries) because the controller records but does not enforc…

▾ Twilightconcretecms · concrete_cmsEPSS 0.30%via NVD
CVE-2026-68535Medium· 4.3
2w ago

Concrete CMS Area API's block-create endpoint in versions 9.2.0 to 9.5.2 did not invoke the block type controller's validate() method on submitted data, which, for file-referencing blocks such as hero_image and gallery, is where the refe…

Concrete CMS Area API's block-create endpoint in versions 9.2.0 to 9.5.2 did not invoke the block type controller's validate() method on submitted data, which, for file-referencing blocks such as hero_image and gallery, is where the refe…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.44%via NVD
CVE-2026-81918Medium· 4.8
2w ago

Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block

Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block. A user with edit_page_contents permissions could store a payload which executes in the browser of any visitor who viewed …

▾ Sunlitconcretecms · concrete_cmsEPSS 0.25%via NVD
CVE-2026-81917Medium· 5.4
2w ago

Concrete CMS below 9.5.3 does not apply HTML output escaping to the file description and tags fields when rendering the Document Library block, so a user with permission to edit file properties could store a script payload that executed …

Concrete CMS below 9.5.3 does not apply HTML output escaping to the file description and tags fields when rendering the Document Library block, so a user with permission to edit file properties could store a script payload that executed …

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-81916Medium· 4.3
2w ago

Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry submission against the entity of the posted form rather than the entity identified by the dashboard route

Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry submission against the entity of the posted form rather than the entity identified by the dashboard route. As a result, a user permitted to add entries to o…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.27%via NVD
CVE-2026-81915Medium· 5.3
2w ago

Concrete CMS below 9.5.3 does not perform an object-level authorization check when a Page Type was updated

Concrete CMS below 9.5.3 does not perform an object-level authorization check when a Page Type was updated. The Types::submit() dashboard controller loaded and saved the Page Type identified by a user-supplied ptID without calling canEdi…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.44%via NVD
CVE-2026-68526Medium· 4.3
2w ago

Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/controllers/dialog/event/duplicate.php) submit() action, which duplicated a calendar event after checking only canA…

Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/controllers/dialog/event/duplicate.php) submit() action, which duplicated a calendar event after checking only canA…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-18122Medium· 6.0
2w ago

Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization; the Concrete CMS REST API's Express entry collection endpoint disabled the per-entry view permission check

Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization; the Concrete CMS REST API's Express entry collection endpoint disabled the per-entry view permission check. An OAuth…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.23%via NVD
CVE-2026-68528Medium· 6.0
2w ago

Concrete CMS RSS Displayer block below version 9.5.3 rendered remote feed item titles without HTML escaping, resulting in stored cross-site scripting

Concrete CMS RSS Displayer block below version 9.5.3 rendered remote feed item titles without HTML escaping, resulting in stored cross-site scripting. An attacker able to control a title in a syndicated feed could execute script in the …

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.38%via NVD
CVE-2026-81909Medium· 5.9
2w ago

Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block alias route, allowing an authenticated editor to disclose and force-delete arbitrary blocks

Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the block alias route (Process::alias() in concrete/controllers/backend/block/process.php).It does not verify that the referenced block is genuinely orphaned on the t…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.44%via CVEORG
CVE-2026-81913Medium· 6.1
2w ago

Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter

Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. An attacker can craft a single link on the site's own domain that sends a user to an arbitrary external site immediately after authenticat…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.62%via NVD
CVE-2026-81912Medium· 5.7
2w ago

Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature

Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature. The dashboard/users/groups/bulkupdate/confirm() endpoint moved the selected group tree nodes without validating an action token, s…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.23%via NVD
CVE-2026-81911Medium· 5.4
2w ago

Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot dialog

Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot dialog. The custom_slot save_template endpoint authorizes the request only against the target board instance (canEditBoardContents()) and then persists…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-81910Medium· 6.5
2w ago

Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values

Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values. Values submitted through the customizer (color channels and other style properties handled by ColorStyl…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.41%via NVD
CVE-2026-81908Medium· 6.0
2w ago

Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows Authenticated Users to Enumerate All Groups

Concrete CMS 9.2.0 to 9.5.2 contain a missing authorization vulnerability in the REST API Groups list endpoint. The listGroups() method in concrete/src/Api/Controller/Groups.php registers a permissions checker callback that unconditional…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.39%via CVEORG
CVE-2026-18121Medium· 6.3
2w ago

Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the caller is permitted to view the calend…

Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the caller is permitted to view the calend…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.29%via NVD
concrete_cms vulnerabilities (CVEs) — page 2 · VulnSea