concretecms records
197 published records for vendor concretecms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 0.5%
- Pre-auth RCE
- 4
- With a fix record
- 58.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')72
- CWE-352 Cross-Site Request Forgery (CSRF)39
- CWE-862 Missing Authorization16
- CWE-639 Authorization Bypass Through User-Controlled Key9
- CWE-20 Improper Input Validation8
- CWE-918 Server-Side Request Forgery (SSRF)7
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
197 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2022-21829No exploit | Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which cconcretecms · concrete cms · CWE-319 | Critical9.8 | — | 1.8% | Jun 24, 2022 |
39Monitor | CVE-2021-40098No exploit | An issue was discovered in Concrete CMS through 8.5.5.concretecms · concrete cms · CWE-22 | Critical9.8 | — | 1.6% | Sep 27, 2021 |
39Monitor | CVE-2023-48648No exploit | Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions.concretecms · concrete cms · CWE-276 | Critical9.8 | — | 1.2% | Nov 17, 2023 |
39Monitor | CVE-2021-22958No exploit | A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the concretecms · concrete cms · CWE-918 | Critical9.8 | — | 1.2% | Oct 7, 2021 |
37Monitor | CVE-2022-30117No exploit | Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 allow traversal in /index.php/ccm/system/file/upload which could result in anconcretecms · concrete cms · CWE-22 | Critical9.1 | — | 2.1% | Jun 24, 2022 |
37Monitor | CVE-2026-8134No exploit | Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemplate Path Traversal leading to PHP File Inclusionconcretecms · concrete cms · CWE-23 | Critical9.4 | — | 1.1% | May 21, 2026 |
36Monitor | CVE-2021-40097No exploit | An issue was discovered in Concrete CMS through 8.5.5.concretecms · concrete cms · CWE-22 | High8.8 | — | 2.5% | Sep 27, 2021 |
36Monitor | CVE-2021-40102No exploit | An issue was discovered in Concrete CMS through 8.5.5.concretecms · concrete cms · CWE-502 | Critical9.1 | — | 1.3% | Sep 24, 2021 |
35Monitor | CVE-2021-22966No exploit | Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below.concretecms · concrete cms · CWE-863 | High8.8 | — | 1.0% | Nov 19, 2021 |
35Monitor | CVE-2026-3452No exploit | Concrete CMS below 9.4.8 is vulnerable to stored deserialization leading to RCE in the Express Entry List block.concretecms · concrete cms · CWE-502 | High8.9 | — | 0.9% | Mar 3, 2026 |
35Monitor | CVE-2015-4724No exploit | SQL injection vulnerability in Concrete5 5.7.3.1.concretecms · concrete cms · CWE-89 | High8.8 | — | 0.8% | Sep 7, 2017 |
35Monitor | CVE-2026-8135No exploit | Concrete CMS 9.5.0 and below is vulnerable to RCE due to insecure deserialization occurring in the ExpressEntryList block controller.concretecms · concrete cms · CWE-502 | High8.9 | — | 0.7% | May 21, 2026 |
35Monitor | CVE-2021-22954No exploit | A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an attacker to make requests on behalf of other usersconcretecms · concrete cms · CWE-352 | High8.8 | — | 0.5% | Feb 9, 2022 |
35Monitor | CVE-2021-40108No exploit | An issue was discovered in Concrete CMS through 8.5.5.concretecms · concrete cms · CWE-352 | High8.8 | — | 0.5% | Sep 27, 2021 |
35Monitor | CVE-2022-43693No exploit | Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for users of Concrete wconcretecms · concrete cms · CWE-352 | High8.8 | — | 0.5% | Nov 14, 2022 |
34Monitor | CVE-2026-81895No exploit | Concrete CMS 9.5.2 and below is vulnerable to Stored SQL Injection in Concrete CMS Document Library Block via `fsID[]` in `setMode=any`concretecms · concrete cms · CWE-89 | High8.5 | — | 0.5% | Sep 15, 2026 |
34Monitor | CVE-2026-18110Proof of concept | Concrete CMS 9.0.0 through 9.5.2 is vulnerable to missing authorization in the user selector autocomplete endpoint (/ccm/system/user/autocomplete), allowing an concretecms · concrete cms · CWE-862 | High8.7 | — | 0.3% | Sep 15, 2026 |
34Monitor | CVE-2026-81894No exploit | Concrete CMS 9.5.2 and below is vulnerable to Stored DOM-based Cross-site Scripting (XSS) in the Gallery block image Caption fieldconcretecms · concrete cms · CWE-89 | High8.5 | — | 0.2% | Sep 15, 2026 |
33Monitor | CVE-2026-81896No exploit | Concrete CMS below version 9.5.3 is vulnerable to Stored XSS in Concrete CMS Form Submissions Report via Unescaped Question Labelconcretecms · concrete cms · CWE-79 | High8.4 | — | 0.2% | Sep 15, 2026 |
30Monitor | CVE-2021-22970No exploit | Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system to be vulnerable toconcretecms · concrete cms · CWE-918 | High7.5 | — | 1.5% | Nov 19, 2021 |
30Monitor | CVE-2021-40103No exploit | An issue was discovered in Concrete CMS through 8.5.5.concretecms · concrete cms · CWE-22 | High7.5 | — | 1.5% | Sep 27, 2021 |
30Monitor | CVE-2021-40104No exploit | An issue was discovered in Concrete CMS through 8.5.5.concretecms · concrete cms | High7.5 | — | 1.4% | Sep 27, 2021 |
30Monitor | CVE-2021-22967No exploit | In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to concretecms · concrete cms · CWE-639 | High7.5 | — | 1.1% | Nov 19, 2021 |
30Monitor | CVE-2021-22951No exploit | Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.concretecms · concrete cms · CWE-639 | High7.5 | — | 1.1% | Nov 19, 2021 |
30Monitor | CVE-2026-85385No exploit | Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone Fieldconcretecms · concrete cms · CWE-79 | High7.7 | — | 0.5% | Sep 16, 2026 |
- CVE-2022-2182940Plan
Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which c
CriticalCVSS 9.8No exploitEPSS 2%concretecms · concrete cmsJun 24, 2022
- CVE-2021-4009839Monitor
An issue was discovered in Concrete CMS through 8.5.5.
CriticalCVSS 9.8No exploitEPSS 2%concretecms · concrete cmsSep 27, 2021
- CVE-2023-4864839Monitor
Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions.
CriticalCVSS 9.8No exploitEPSS 1%concretecms · concrete cmsNov 17, 2023
- CVE-2021-2295839Monitor
A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the
CriticalCVSS 9.8No exploitEPSS 1%concretecms · concrete cmsOct 7, 2021
- CVE-2022-3011737Monitor
Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 allow traversal in /index.php/ccm/system/file/upload which could result in an
CriticalCVSS 9.1No exploitEPSS 2%concretecms · concrete cmsJun 24, 2022
- CVE-2026-813437Monitor
Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemplate Path Traversal leading to PHP File Inclusion
CriticalCVSS 9.4No exploitEPSS 1%concretecms · concrete cmsMay 21, 2026
- CVE-2021-4009736Monitor
An issue was discovered in Concrete CMS through 8.5.5.
HighCVSS 8.8No exploitEPSS 3%concretecms · concrete cmsSep 27, 2021
- CVE-2021-4010236Monitor
An issue was discovered in Concrete CMS through 8.5.5.
CriticalCVSS 9.1No exploitEPSS 1%concretecms · concrete cmsSep 24, 2021
- CVE-2021-2296635Monitor
Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below.
HighCVSS 8.8No exploitEPSS 1%concretecms · concrete cmsNov 19, 2021
- CVE-2026-345235Monitor
Concrete CMS below 9.4.8 is vulnerable to stored deserialization leading to RCE in the Express Entry List block.
HighCVSS 8.9No exploitEPSS 1%concretecms · concrete cmsMar 3, 2026
- CVE-2015-472435Monitor
SQL injection vulnerability in Concrete5 5.7.3.1.
HighCVSS 8.8No exploitEPSS 1%concretecms · concrete cmsSep 7, 2017
- CVE-2026-813535Monitor
Concrete CMS 9.5.0 and below is vulnerable to RCE due to insecure deserialization occurring in the ExpressEntryList block controller.
HighCVSS 8.9No exploitEPSS 1%concretecms · concrete cmsMay 21, 2026
- CVE-2021-2295435Monitor
A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an attacker to make requests on behalf of other users
HighCVSS 8.8No exploitEPSS 1%concretecms · concrete cmsFeb 9, 2022
- CVE-2021-4010835Monitor
An issue was discovered in Concrete CMS through 8.5.5.
HighCVSS 8.8No exploitEPSS 0%concretecms · concrete cmsSep 27, 2021
- CVE-2022-4369335Monitor
Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for users of Concrete w
HighCVSS 8.8No exploitEPSS 0%concretecms · concrete cmsNov 14, 2022
- CVE-2026-8189534Monitor
Concrete CMS 9.5.2 and below is vulnerable to Stored SQL Injection in Concrete CMS Document Library Block via `fsID[]` in `setMode=any`
HighCVSS 8.5No exploitEPSS 1%concretecms · concrete cmsSep 15, 2026
- CVE-2026-1811034Monitor
Concrete CMS 9.0.0 through 9.5.2 is vulnerable to missing authorization in the user selector autocomplete endpoint (/ccm/system/user/autocomplete), allowing an
HighCVSS 8.7Proof of conceptEPSS 0%concretecms · concrete cmsSep 15, 2026
- CVE-2026-8189434Monitor
Concrete CMS 9.5.2 and below is vulnerable to Stored DOM-based Cross-site Scripting (XSS) in the Gallery block image Caption field
HighCVSS 8.5No exploitEPSS 0%concretecms · concrete cmsSep 15, 2026
- CVE-2026-8189633Monitor
Concrete CMS below version 9.5.3 is vulnerable to Stored XSS in Concrete CMS Form Submissions Report via Unescaped Question Label
HighCVSS 8.4No exploitEPSS 0%concretecms · concrete cmsSep 15, 2026
- CVE-2021-2297030Monitor
Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system to be vulnerable to
HighCVSS 7.5No exploitEPSS 1%concretecms · concrete cmsNov 19, 2021
- CVE-2021-4010330Monitor
An issue was discovered in Concrete CMS through 8.5.5.
HighCVSS 7.5No exploitEPSS 1%concretecms · concrete cmsSep 27, 2021
- CVE-2021-4010430Monitor
An issue was discovered in Concrete CMS through 8.5.5.
HighCVSS 7.5No exploitEPSS 1%concretecms · concrete cmsSep 27, 2021
- CVE-2021-2296730Monitor
In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to
HighCVSS 7.5No exploitEPSS 1%concretecms · concrete cmsNov 19, 2021
- CVE-2021-2295130Monitor
Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.
HighCVSS 7.5No exploitEPSS 1%concretecms · concrete cmsNov 19, 2021
- CVE-2026-8538530Monitor
Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone Field
HighCVSS 7.7No exploitEPSS 1%concretecms · concrete cmsSep 16, 2026