Concrete cms
This hub aggregates every CVE we track for Concrete cms, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
154
CVEs tracked
6
Critical
38
High
0
In CISA KEV
Severity distribution
MEDIUM96HIGH38LOW14CRITICAL6
Monthly trend
4
0
0
0
0
0
1
1
0
0
0
2
0
0
0
0
0
0
7
0
44
0
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Concrete cms.
- CVE-2026-8353Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in atomik theme4.8
- CVE-2026-8347Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialog4.3
- CVE-2026-8340Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion4.3
- CVE-2026-8139Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName5.4
- CVE-2026-7890Concrete CMS 9.5.0 is vulnerable to SSRF via RSS Displayer Block6.4
- CVE-2026-8409Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete8.8
- CVE-2026-8410Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete8.8
- CVE-2026-8411Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete8.8
- CVE-2026-8412Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache8.8
- CVE-2026-8413Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design8.8
- CVE-2026-8414Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate8.8
- CVE-2026-8415Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder8.8
- CVE-2026-8416Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id)8.8
- CVE-2026-8427Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id)8.8
- CVE-2026-8432Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star()8.8
Product normalization is registry-driven with AI assist and human review. How it works