Skip to content
Noroxi

concretecms records

197 published records for vendor concretecms.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 0.5%
Pre-auth RCE
4
With a fix record
58.9%
Median publish → KEV
No record has entered KEV

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

197 records
  • Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which c

    CriticalCVSS 9.8No exploitEPSS 2%

    concretecms · concrete cmsJun 24, 2022

  • An issue was discovered in Concrete CMS through 8.5.5.

    CriticalCVSS 9.8No exploitEPSS 2%

    concretecms · concrete cmsSep 27, 2021

  • Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions.

    CriticalCVSS 9.8No exploitEPSS 1%

    concretecms · concrete cmsNov 17, 2023

  • A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the

    CriticalCVSS 9.8No exploitEPSS 1%

    concretecms · concrete cmsOct 7, 2021

  • Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 allow traversal in /index.php/ccm/system/file/upload which could result in an

    CriticalCVSS 9.1No exploitEPSS 2%

    concretecms · concrete cmsJun 24, 2022

  • CVE-2026-8134
    37Monitor

    Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemplate Path Traversal leading to PHP File Inclusion

    CriticalCVSS 9.4No exploitEPSS 1%

    concretecms · concrete cmsMay 21, 2026

  • An issue was discovered in Concrete CMS through 8.5.5.

    HighCVSS 8.8No exploitEPSS 3%

    concretecms · concrete cmsSep 27, 2021

  • An issue was discovered in Concrete CMS through 8.5.5.

    CriticalCVSS 9.1No exploitEPSS 1%

    concretecms · concrete cmsSep 24, 2021

  • Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below.

    HighCVSS 8.8No exploitEPSS 1%

    concretecms · concrete cmsNov 19, 2021

  • CVE-2026-3452
    35Monitor

    Concrete CMS below 9.4.8 is vulnerable to stored deserialization leading to RCE in the Express Entry List block.

    HighCVSS 8.9No exploitEPSS 1%

    concretecms · concrete cmsMar 3, 2026

  • CVE-2015-4724
    35Monitor

    SQL injection vulnerability in Concrete5 5.7.3.1.

    HighCVSS 8.8No exploitEPSS 1%

    concretecms · concrete cmsSep 7, 2017

  • CVE-2026-8135
    35Monitor

    Concrete CMS 9.5.0 and below is vulnerable to RCE due to insecure deserialization occurring in the ExpressEntryList block controller.

    HighCVSS 8.9No exploitEPSS 1%

    concretecms · concrete cmsMay 21, 2026

  • A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an attacker to make requests on behalf of other users

    HighCVSS 8.8No exploitEPSS 1%

    concretecms · concrete cmsFeb 9, 2022

  • An issue was discovered in Concrete CMS through 8.5.5.

    HighCVSS 8.8No exploitEPSS 0%

    concretecms · concrete cmsSep 27, 2021

  • Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for users of Concrete w

    HighCVSS 8.8No exploitEPSS 0%

    concretecms · concrete cmsNov 14, 2022

  • Concrete CMS 9.5.2 and below is vulnerable to Stored SQL Injection in Concrete CMS Document Library Block via `fsID[]` in `setMode=any`

    HighCVSS 8.5No exploitEPSS 1%

    concretecms · concrete cmsSep 15, 2026

  • Concrete CMS 9.0.0 through 9.5.2 is vulnerable to missing authorization in the user selector autocomplete endpoint (/ccm/system/user/autocomplete), allowing an

    HighCVSS 8.7Proof of conceptEPSS 0%

    concretecms · concrete cmsSep 15, 2026

  • Concrete CMS 9.5.2 and below is vulnerable to Stored DOM-based Cross-site Scripting (XSS) in the Gallery block image Caption field

    HighCVSS 8.5No exploitEPSS 0%

    concretecms · concrete cmsSep 15, 2026

  • Concrete CMS below version 9.5.3 is vulnerable to Stored XSS in Concrete CMS Form Submissions Report via Unescaped Question Label

    HighCVSS 8.4No exploitEPSS 0%

    concretecms · concrete cmsSep 15, 2026

  • Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system to be vulnerable to

    HighCVSS 7.5No exploitEPSS 1%

    concretecms · concrete cmsNov 19, 2021

  • An issue was discovered in Concrete CMS through 8.5.5.

    HighCVSS 7.5No exploitEPSS 1%

    concretecms · concrete cmsSep 27, 2021

  • An issue was discovered in Concrete CMS through 8.5.5.

    HighCVSS 7.5No exploitEPSS 1%

    concretecms · concrete cmsSep 27, 2021

  • In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to

    HighCVSS 7.5No exploitEPSS 1%

    concretecms · concrete cmsNov 19, 2021

  • Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.

    HighCVSS 7.5No exploitEPSS 1%

    concretecms · concrete cmsNov 19, 2021

  • Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone Field

    HighCVSS 7.7No exploitEPSS 1%

    concretecms · concrete cmsSep 16, 2026