VulnSea

Concrete CMS has 30 CVEs on record. Disclosure cadence is accelerating: 29 in the last 90 days against 1 in the 90 before. The busiest recent month was September 2026 with 29. The median CVSS is 6.0 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-862 (12) and CWE-79 (6).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.0
Publish → KEV
Last 90 days
29 prev 1

Products

  • Concrete CMS 30
30
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

Concrete CMS vulnerabilities

CVEs affecting Concrete CMS, newest first. Open any entry for full detail, references, and exploit status.

30 CVEsRSS

CVE-2026-68532Low· 2.3
1w ago

Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cross-site request forgery

Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cross-site request forgery. A remote unauthenticated attacker could cause an authenticated user with group type manage…

SunlitConcrete CMS · Concrete CMSEPSS 0.21%via NVD
CVE-2026-68531Low· 2.1
1w ago

Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard characters in the keyword search filters used by the file manager, file folders, and page list, allowing an authenticated user with editor-level or higher privileges to submit …

Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard characters in the keyword search filters used by the file manager, file folders, and page list, allowing an authenticated user with editor-level or higher privileges to submit …

SunlitConcrete CMS · Concrete CMSEPSS 0.29%via NVD
CVE-2026-68530Low· 2.1
1w ago

Concrete CMS 9 through 9.5.2 did not perform an authorization check on several board-instance actions in the Boards area of the Dashboard

Concrete CMS 9 through 9.5.2 did not perform an authorization check on several board-instance actions in the Boards area of the Dashboard. The instance details single-page controller resolved a board instance directly from an attacker-su…

SunlitConcrete CMS · Concrete CMSEPSS 0.29%via NVD
CVE-2026-68529Low· 2.1
1w ago

Concrete CMS 9.0.0 through 9.5.2 was missing an authorization check on the Express entries advanced-search dashboard action

Concrete CMS 9.0.0 through 9.5.2 was missing an authorization check on the Express entries advanced-search dashboard action. The advanced_search() method in DashboardSelectableExpressEntryListTrait resolved an Express entity directly fro…

SunlitConcrete CMS · Concrete CMSEPSS 0.27%via NVD
CVE-2026-18421Low· 2.1
1w ago

Concrete CMS 9 through 9.5.2 does not perform an authorization check in three actions of the Boards data source dashboard controller (update, update_data_source, and delete_data_source), which resolve a ConfiguredDataSource directly from…

Concrete CMS 9 through 9.5.2 does not perform an authorization check in three actions of the Boards data source dashboard controller (update, update_data_source, and delete_data_source), which resolve a ConfiguredDataSource directly from…

SunlitConcrete CMS · Concrete CMSEPSS 0.27%via NVD
CVE-2026-68534Low· 2.3
1w ago

Concrete CMS before 9.5.3 rendered Express entry labels as raw HTML when displaying associated entries, resulting in stored cross-site scripting

Concrete CMS before 9.5.3 rendered Express entry labels as raw HTML when displaying associated entries, resulting in stored cross-site scripting. An unauthenticated attacker could submit a payload through a public Express Form; it then e…

SunlitConcrete CMS · Concrete CMSEPSS 0.41%via NVD
CVE-2026-68533Low· 2.3
1w ago

Concrete CMS below 9.5.3 conversation attachment uploaded endpoint imported files into the file manager before evaluating the "Add Message Attachments" permission, which was only checked after the file had been stored

Concrete CMS below 9.5.3 conversation attachment uploaded endpoint imported files into the file manager before evaluating the "Add Message Attachments" permission, which was only checked after the file had been stored. A user denied that…

SunlitConcrete CMS · Concrete CMSEPSS 0.29%via NVD
CVE-2026-81899High· 7.3
1w ago

Concrete CMS 9.0.0 to 9.5.2 stored group folder names without sanitization and printed them unescaped on the Members > Groups dashboard page, resulting in stored cross-site scripting

Concrete CMS 9.0.0 to 9.5.2 stored group folder names without sanitization and printed them unescaped on the Members > Groups dashboard page, resulting in stored cross-site scripting. The add and edit group-folder handlers stored the sub…

TwilightConcrete CMS · Concrete CMSEPSS 0.31%via NVD
CVE-2026-18115High· 7.4
1w ago

Concrete CMS 9.2.0 to 9.5.2 did not enforce per-field edit_user_properties permissions on the REST API user write endpoints (PUT /ccm/api/1.0/users/{uID} and POST /ccm/api/1.0/users/{uID}/change_password)

Concrete CMS 9.2.0 to 9.5.2 did not enforce per-field edit_user_properties permissions on the REST API user write endpoints (PUT /ccm/api/1.0/users/{uID} and POST /ccm/api/1.0/users/{uID}/change_password). A user with an update-scoped OA…

TwilightConcrete CMS · Concrete CMSEPSS 0.26%via NVD
CVE-2026-81898High· 7.5
1w ago

In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stored XSS in Express association views

In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stored XSS in Express association views. A user able to submit an Address attribute could execute script in the sess…

TwilightConcrete CMS · Concrete CMSEPSS 0.26%via NVD
CVE-2026-18113High· 7.5
1w ago

In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing them into the page, so a user who could create or rename pages could store a script through a child page name and hav…

In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing them into the page, so a user who could create or rename pages could store a script through a child page name and hav…

TwilightConcrete CMS · Concrete CMSEPSS 0.29%via NVD
CVE-2026-18111High· 8.5
1w ago

Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image, and Image blocks and before Concrete 8.5.21 in the feature and Image blocks because the external link URL was insuf…

Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image, and Image blocks and before Concrete 8.5.21 in the feature and Image blocks because the external link URL was insuf…

TwilightConcrete CMS · Concrete CMSEPSS 0.34%via NVD
CVE-2026-18117High· 7.3
1w ago

Concrete CMS 9.0.0 through 9.5.3 is vulnerable to stored XSS via the custom page alias name (customAliasName) because the Edit Alias dialog applied only trim() to the submitted value and performed no input neutralization

Concrete CMS 9.0.0 through 9.5.3 is vulnerable to stored XSS via the custom page alias name (customAliasName) because the Edit Alias dialog applied only trim() to the submitted value and performed no input neutralization. An authenticate…

TwilightConcrete CMS · Concrete CMSEPSS 0.31%via NVD
CVE-2026-81907Medium· 6.1
1w ago

Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function (POST /index.php/dashboard/system/express/entities/delete_entries) because the controller records but does not enforc…

Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function (POST /index.php/dashboard/system/express/entities/delete_entries) because the controller records but does not enforc…

SunlitConcrete CMS · Concrete CMSEPSS 0.21%via NVD
CVE-2026-68535Medium· 5.1
1w ago

Concrete CMS Area API's block-create endpoint in versions 9.2.0 to 9.5.2 did not invoke the block type controller's validate() method on submitted data, which, for file-referencing blocks such as hero_image and gallery, is where the refe…

Concrete CMS Area API's block-create endpoint in versions 9.2.0 to 9.5.2 did not invoke the block type controller's validate() method on submitted data, which, for file-referencing blocks such as hero_image and gallery, is where the refe…

SunlitConcrete CMS · Concrete CMSEPSS 0.32%via NVD
CVE-2026-81915Medium· 5.1
1w ago

Concrete CMS below 9.5.3 does not perform an object-level authorization check when a Page Type was updated

Concrete CMS below 9.5.3 does not perform an object-level authorization check when a Page Type was updated. The Types::submit() dashboard controller loaded and saved the Page Type identified by a user-supplied ptID without calling canEdi…

SunlitConcrete CMS · Concrete CMSEPSS 0.42%via NVD
CVE-2026-68526Medium· 5.3
1w ago

Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/controllers/dialog/event/duplicate.php) submit() action, which duplicated a calendar event after checking only canA…

Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/controllers/dialog/event/duplicate.php) submit() action, which duplicated a calendar event after checking only canA…

SunlitConcrete CMS · Concrete CMSEPSS 0.18%via NVD
CVE-2026-18122Medium· 6.0
1w ago

Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization; the Concrete CMS REST API's Express entry collection endpoint disabled the per-entry view permission check

Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization; the Concrete CMS REST API's Express entry collection endpoint disabled the per-entry view permission check. An OAuth…

SunlitConcrete CMS · Concrete CMSEPSS 0.23%via NVD
CVE-2026-68528Medium· 6.0
1w ago

Concrete CMS RSS Displayer block below version 9.5.3 rendered remote feed item titles without HTML escaping, resulting in stored cross-site scripting

Concrete CMS RSS Displayer block below version 9.5.3 rendered remote feed item titles without HTML escaping, resulting in stored cross-site scripting. An attacker able to control a title in a syndicated feed could execute script in the …

SunlitConcrete CMS · Concrete CMSEPSS 0.24%via NVD
CVE-2026-81909Medium· 5.9
1w ago

Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block alias route, allowing an authenticated editor to disclose and force-delete arbitrary blocks

Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the block alias route (Process::alias() in concrete/controllers/backend/block/process.php).It does not verify that the referenced block is genuinely orphaned on the t…

SunlitConcrete CMS · Concrete CMSEPSS 0.26%via CVEORG
CVE-2026-81913Medium· 5.3
1w ago

Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter

Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. An attacker can craft a single link on the site's own domain that sends a user to an arbitrary external site immediately after authenticat…

SunlitConcrete CMS · Concrete CMSEPSS 0.59%via NVD
CVE-2026-81912Medium· 5.7
1w ago

Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature

Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature. The dashboard/users/groups/bulkupdate/confirm() endpoint moved the selected group tree nodes without validating an action token, s…

SunlitConcrete CMS · Concrete CMSEPSS 0.18%via NVD
CVE-2026-81908Medium· 6.0
1w ago

Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows Authenticated Users to Enumerate All Groups

Concrete CMS 9.2.0 to 9.5.2 contain a missing authorization vulnerability in the REST API Groups list endpoint. The listGroups() method in concrete/src/Api/Controller/Groups.php registers a permissions checker callback that unconditional…

SunlitConcrete CMS · Concrete CMSEPSS 0.23%via CVEORG
CVE-2026-18121Medium· 6.3
1w ago

Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the caller is permitted to view the calend…

Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the caller is permitted to view the calend…

SunlitConcrete CMS · Concrete CMSEPSS 0.29%via NVD
CVE-2026-81905Medium· 6.3
1w ago

Concrete CMS below 9.5.3 stores user validation hashes for multiple purposes (email/registration validation, password reset, and persistent login) in a single table with a type column, but the redemption path resolves a hash by value alo…

Concrete CMS below 9.5.3 stores user validation hashes for multiple purposes (email/registration validation, password reset, and persistent login) in a single table with a type column, but the redemption path resolves a hash by value alo…

SunlitConcrete CMS · Concrete CMSEPSS 0.24%via NVD
CVE-2026-81906Medium· 6.3
1w ago

Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session

Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete a…

SunlitConcrete CMS · Concrete CMSEPSS 0.39%via NVD
CVE-2026-84432Medium· 5.3
1w ago

Concrete CMS 9 through 9.5.2 did not validate an anti-CSRF token in the Boards custom slot dialog controller (concrete/controllers/dialog/board/custom_slot.php) saveTemplate() action

Concrete CMS 9 through 9.5.2 did not validate an anti-CSRF token in the Boards custom slot dialog controller (concrete/controllers/dialog/board/custom_slot.php) saveTemplate() action. The action created a board_slot_proxy Block and disp…

SunlitConcrete CMS · Concrete CMSEPSS 0.17%via NVD
CVE-2026-68527Medium· 5.9
1w ago

Concrete CMS 8.3.0 through 9.5.2 is vulnerable to an authorization bypass through user-controlled key (cross-calendar IDOR) in the Calendar event edit dialog

Concrete CMS versions 8.3.0 through 9.5.2 are vulnerable to an authorization bypass in the Calendar event edit dialog (concrete/controllers/dialog/event/edit.php). The dialog checked permissions against the calendar identifier supplied i…

SunlitConcrete CMS · Concrete CMSEPSS 0.28%via CVEORG
CVE-2026-81904Medium· 6.3
2w ago

Concrete CMS below 9.5.3 registered view assets for every sub-block of a Stack, Container, or layout area without checking whether the requesting user could view that sub-block

Concrete CMS below 9.5.3 registered view assets for every sub-block of a Stack, Container, or layout area without checking whether the requesting user could view that sub-block. An unauthenticated visitor could recover configuration valu…

SunlitConcrete CMS · Concrete CMSEPSS 0.28%via NVD
CVE-2026-7888High· 8.4
3mo ago

Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction.

Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. The Form block and File/Set sinks were addressed in 9.…

TwilightConcrete CMS · Concrete CMSEPSS 0.15%via CVEORG
Concrete CMS vulnerabilities (CVEs) · VulnSea