concretecms kayıtları
concretecms üreticisine ait 196 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %0,5
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %58,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')72
- CWE-352 Cross-Site Request Forgery (CSRF)39
- CWE-862 Missing Authorization16
- CWE-639 Authorization Bypass Through User-Controlled Key9
- CWE-20 Improper Input Validation8
- CWE-918 Server-Side Request Forgery (SSRF)7
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
196 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2022-21829İstismar yok | Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which cconcretecms · concrete cms · CWE-319 | Kritik9,8 | — | %1,8 | 24 Haz 2022 |
39İzleyin | CVE-2021-40098İstismar yok | An issue was discovered in Concrete CMS through 8.5.5.concretecms · concrete cms · CWE-22 | Kritik9,8 | — | %1,6 | 27 Eyl 2021 |
39İzleyin | CVE-2023-48648İstismar yok | Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions.concretecms · concrete cms · CWE-276 | Kritik9,8 | — | %1,2 | 17 Kas 2023 |
39İzleyin | CVE-2021-22958İstismar yok | A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the concretecms · concrete cms · CWE-918 | Kritik9,8 | — | %1,2 | 7 Eki 2021 |
37İzleyin | CVE-2022-30117İstismar yok | Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 allow traversal in /index.php/ccm/system/file/upload which could result in anconcretecms · concrete cms · CWE-22 | Kritik9,1 | — | %2,1 | 24 Haz 2022 |
37İzleyin | CVE-2026-8134İstismar yok | Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemplate Path Traversal leading to PHP File Inclusionconcretecms · concrete cms · CWE-23 | Kritik9,4 | — | %1,1 | 21 May 2026 |
36İzleyin | CVE-2021-40097İstismar yok | An issue was discovered in Concrete CMS through 8.5.5.concretecms · concrete cms · CWE-22 | Yüksek8,8 | — | %2,5 | 27 Eyl 2021 |
36İzleyin | CVE-2021-40102İstismar yok | An issue was discovered in Concrete CMS through 8.5.5.concretecms · concrete cms · CWE-502 | Kritik9,1 | — | %1,3 | 24 Eyl 2021 |
35İzleyin | CVE-2021-22966İstismar yok | Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below.concretecms · concrete cms · CWE-863 | Yüksek8,8 | — | %1,0 | 19 Kas 2021 |
35İzleyin | CVE-2026-3452İstismar yok | Concrete CMS below 9.4.8 is vulnerable to stored deserialization leading to RCE in the Express Entry List block.concretecms · concrete cms · CWE-502 | Yüksek8,9 | — | %0,9 | 3 Mar 2026 |
35İzleyin | CVE-2015-4724İstismar yok | SQL injection vulnerability in Concrete5 5.7.3.1.concretecms · concrete cms · CWE-89 | Yüksek8,8 | — | %0,8 | 7 Eyl 2017 |
35İzleyin | CVE-2026-8135İstismar yok | Concrete CMS 9.5.0 and below is vulnerable to RCE due to insecure deserialization occurring in the ExpressEntryList block controller.concretecms · concrete cms · CWE-502 | Yüksek8,9 | — | %0,7 | 21 May 2026 |
35İzleyin | CVE-2021-22954İstismar yok | A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an attacker to make requests on behalf of other usersconcretecms · concrete cms · CWE-352 | Yüksek8,8 | — | %0,5 | 9 Şub 2022 |
35İzleyin | CVE-2021-40108İstismar yok | An issue was discovered in Concrete CMS through 8.5.5.concretecms · concrete cms · CWE-352 | Yüksek8,8 | — | %0,5 | 27 Eyl 2021 |
35İzleyin | CVE-2022-43693İstismar yok | Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for users of Concrete wconcretecms · concrete cms · CWE-352 | Yüksek8,8 | — | %0,5 | 14 Kas 2022 |
34İzleyin | CVE-2026-81895İstismar yok | Concrete CMS 9.5.2 and below is vulnerable to Stored SQL Injection in Concrete CMS Document Library Block via `fsID[]` in `setMode=any`concretecms · concrete cms · CWE-89 | Yüksek8,5 | — | %0,5 | 15 Eyl 2026 |
34İzleyin | CVE-2026-18110Kavram kanıtı | Concrete CMS 9.0.0 through 9.5.2 is vulnerable to missing authorization in the user selector autocomplete endpoint (/ccm/system/user/autocomplete), allowing an concretecms · concrete cms · CWE-862 | Yüksek8,7 | — | %0,3 | 15 Eyl 2026 |
34İzleyin | CVE-2026-81894İstismar yok | Concrete CMS 9.5.2 and below is vulnerable to Stored DOM-based Cross-site Scripting (XSS) in the Gallery block image Caption fieldconcretecms · concrete cms · CWE-89 | Yüksek8,5 | — | %0,2 | 15 Eyl 2026 |
33İzleyin | CVE-2026-81896İstismar yok | Concrete CMS below version 9.5.3 is vulnerable to Stored XSS in Concrete CMS Form Submissions Report via Unescaped Question Labelconcretecms · concrete cms · CWE-79 | Yüksek8,4 | — | %0,2 | 15 Eyl 2026 |
30İzleyin | CVE-2021-22970İstismar yok | Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system to be vulnerable toconcretecms · concrete cms · CWE-918 | Yüksek7,5 | — | %1,5 | 19 Kas 2021 |
30İzleyin | CVE-2021-40103İstismar yok | An issue was discovered in Concrete CMS through 8.5.5.concretecms · concrete cms · CWE-22 | Yüksek7,5 | — | %1,5 | 27 Eyl 2021 |
30İzleyin | CVE-2021-40104İstismar yok | An issue was discovered in Concrete CMS through 8.5.5.concretecms · concrete cms | Yüksek7,5 | — | %1,4 | 27 Eyl 2021 |
30İzleyin | CVE-2021-22967İstismar yok | In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to concretecms · concrete cms · CWE-639 | Yüksek7,5 | — | %1,1 | 19 Kas 2021 |
30İzleyin | CVE-2021-22951İstismar yok | Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.concretecms · concrete cms · CWE-639 | Yüksek7,5 | — | %1,1 | 19 Kas 2021 |
30İzleyin | CVE-2026-85385İstismar yok | Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone Fieldconcretecms · concrete cms · CWE-79 | Yüksek7,7 | — | %0,5 | 16 Eyl 2026 |
- CVE-2022-2182940Planlayın
Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which c
KritikCVSS 9,8İstismar yokEPSS %2concretecms · concrete cms24 Haz 2022
- CVE-2021-4009839İzleyin
An issue was discovered in Concrete CMS through 8.5.5.
KritikCVSS 9,8İstismar yokEPSS %2concretecms · concrete cms27 Eyl 2021
- CVE-2023-4864839İzleyin
Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions.
KritikCVSS 9,8İstismar yokEPSS %1concretecms · concrete cms17 Kas 2023
- CVE-2021-2295839İzleyin
A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the
KritikCVSS 9,8İstismar yokEPSS %1concretecms · concrete cms7 Eki 2021
- CVE-2022-3011737İzleyin
Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 allow traversal in /index.php/ccm/system/file/upload which could result in an
KritikCVSS 9,1İstismar yokEPSS %2concretecms · concrete cms24 Haz 2022
- CVE-2026-813437İzleyin
Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemplate Path Traversal leading to PHP File Inclusion
KritikCVSS 9,4İstismar yokEPSS %1concretecms · concrete cms21 May 2026
- CVE-2021-4009736İzleyin
An issue was discovered in Concrete CMS through 8.5.5.
YüksekCVSS 8,8İstismar yokEPSS %3concretecms · concrete cms27 Eyl 2021
- CVE-2021-4010236İzleyin
An issue was discovered in Concrete CMS through 8.5.5.
KritikCVSS 9,1İstismar yokEPSS %1concretecms · concrete cms24 Eyl 2021
- CVE-2021-2296635İzleyin
Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below.
YüksekCVSS 8,8İstismar yokEPSS %1concretecms · concrete cms19 Kas 2021
- CVE-2026-345235İzleyin
Concrete CMS below 9.4.8 is vulnerable to stored deserialization leading to RCE in the Express Entry List block.
YüksekCVSS 8,9İstismar yokEPSS %1concretecms · concrete cms3 Mar 2026
- CVE-2015-472435İzleyin
SQL injection vulnerability in Concrete5 5.7.3.1.
YüksekCVSS 8,8İstismar yokEPSS %1concretecms · concrete cms7 Eyl 2017
- CVE-2026-813535İzleyin
Concrete CMS 9.5.0 and below is vulnerable to RCE due to insecure deserialization occurring in the ExpressEntryList block controller.
YüksekCVSS 8,9İstismar yokEPSS %1concretecms · concrete cms21 May 2026
- CVE-2021-2295435İzleyin
A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an attacker to make requests on behalf of other users
YüksekCVSS 8,8İstismar yokEPSS %1concretecms · concrete cms9 Şub 2022
- CVE-2021-4010835İzleyin
An issue was discovered in Concrete CMS through 8.5.5.
YüksekCVSS 8,8İstismar yokEPSS %0concretecms · concrete cms27 Eyl 2021
- CVE-2022-4369335İzleyin
Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for users of Concrete w
YüksekCVSS 8,8İstismar yokEPSS %0concretecms · concrete cms14 Kas 2022
- CVE-2026-8189534İzleyin
Concrete CMS 9.5.2 and below is vulnerable to Stored SQL Injection in Concrete CMS Document Library Block via `fsID[]` in `setMode=any`
YüksekCVSS 8,5İstismar yokEPSS %1concretecms · concrete cms15 Eyl 2026
- CVE-2026-1811034İzleyin
Concrete CMS 9.0.0 through 9.5.2 is vulnerable to missing authorization in the user selector autocomplete endpoint (/ccm/system/user/autocomplete), allowing an
YüksekCVSS 8,7Kavram kanıtıEPSS %0concretecms · concrete cms15 Eyl 2026
- CVE-2026-8189434İzleyin
Concrete CMS 9.5.2 and below is vulnerable to Stored DOM-based Cross-site Scripting (XSS) in the Gallery block image Caption field
YüksekCVSS 8,5İstismar yokEPSS %0concretecms · concrete cms15 Eyl 2026
- CVE-2026-8189633İzleyin
Concrete CMS below version 9.5.3 is vulnerable to Stored XSS in Concrete CMS Form Submissions Report via Unescaped Question Label
YüksekCVSS 8,4İstismar yokEPSS %0concretecms · concrete cms15 Eyl 2026
- CVE-2021-2297030İzleyin
Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system to be vulnerable to
YüksekCVSS 7,5İstismar yokEPSS %1concretecms · concrete cms19 Kas 2021
- CVE-2021-4010330İzleyin
An issue was discovered in Concrete CMS through 8.5.5.
YüksekCVSS 7,5İstismar yokEPSS %1concretecms · concrete cms27 Eyl 2021
- CVE-2021-4010430İzleyin
An issue was discovered in Concrete CMS through 8.5.5.
YüksekCVSS 7,5İstismar yokEPSS %1concretecms · concrete cms27 Eyl 2021
- CVE-2021-2296730İzleyin
In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to
YüksekCVSS 7,5İstismar yokEPSS %1concretecms · concrete cms19 Kas 2021
- CVE-2021-2295130İzleyin
Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.
YüksekCVSS 7,5İstismar yokEPSS %1concretecms · concrete cms19 Kas 2021
- CVE-2026-8538530İzleyin
Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone Field
YüksekCVSS 7,7İstismar yokEPSS %1concretecms · concrete cms16 Eyl 2026