Concrete5/concrete5
This hub aggregates every CVE we track for Concrete5/concrete5, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
72
CVEs tracked
2
Critical
4
High
0
In CISA KEV
Severity distribution
MEDIUM52LOW14HIGH4CRITICAL2
Monthly trend
4
4
0
0
0
0
0
1
1
0
0
0
2
0
0
0
0
0
0
6
0
0
0
0
2024-082026-07
Latest CVEs
The 15 most recently published vulnerabilities affecting Concrete5/concrete5.
- CVE-2026-2994Concrete CMS below 9.4.8 is vulnerable to CSRF by a Rogue Admin using the Anti-Spam Allowlist Group6.8
- CVE-2026-3240Concrete CMS below 9.4.8 is vulnerable to Stored XSS via Legacy form4.8
- CVE-2026-3241Concrete CMS below version 9.4.8 is vulnerable to a stored cross-site scripting (XSS) in the "Legacy Form" block.4.8
- CVE-2026-3242Concrete CMS below 9.4.8 is vulnerable to Stored XSS in the Switch Language block4.8
- CVE-2026-3244Concrete CMS below version 9.4.8 is vulnerable to Stored XSS in Search Results via Page Names4.8
- CVE-2026-3452Concrete CMS below 9.4.8 is vulnerable to stored deserialization leading to RCE in the Express Entry List block.7.2
- CVE-2025-8571Concrete CMS 9 through 9.4.2 and below 8.5.21 is vulnerable to Reflected Cross-Site Scripting (XSS) in Conversation Messages Dashboard Page4.8
- CVE-2025-8573Concrete CMS 9 through 9.4.2 is vulnerable to Stored XSS from Home Folder on Members Dashboard page4.8
- CVE-2025-3153Concrete CMS version 9 below 9.4.0RC2 and versions below 8.5.20 - CSRF and XSS in Concrete CMS Custom Address attribute6.5
- CVE-2025-0660Stored XSS in Folder Function by Rogue Admin4.8
- CVE-2024-7398Concrete CMS Stored XSS Vulnerability in Calendar Event Addition Feature5.4
- CVE-2024-8291Concrete CMS Stored XSS in Image Editor Background Color4.8
- CVE-2024-8660Stored XSS in the "Top Navigator Bar" block4.8
- CVE-2024-8661Concrete CMS version 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" block4.8
- CVE-2024-4350Concrete CMS version 9 below 9.3.3 and below 8.5.18 are vulnerable to Stored XSS in RSS Displayer4.8
Product normalization is registry-driven with AI assist and human review. How it works