İçeriğe atla
Noroxi

concretecms kayıtları

concretecms üreticisine ait 196 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
1 · %0,5
Pre-auth RCE
4
Düzeltme kaydı olan
%58,9
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

196 kayıt
  • CVE-2022-21829
    40Planlayın

    Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which c

    KritikCVSS 9,8İstismar yokEPSS %2

    concretecms · concrete cms24 Haz 2022

  • CVE-2021-40098
    39İzleyin

    An issue was discovered in Concrete CMS through 8.5.5.

    KritikCVSS 9,8İstismar yokEPSS %2

    concretecms · concrete cms27 Eyl 2021

  • CVE-2023-48648
    39İzleyin

    Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions.

    KritikCVSS 9,8İstismar yokEPSS %1

    concretecms · concrete cms17 Kas 2023

  • CVE-2021-22958
    39İzleyin

    A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the

    KritikCVSS 9,8İstismar yokEPSS %1

    concretecms · concrete cms7 Eki 2021

  • CVE-2022-30117
    37İzleyin

    Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 allow traversal in /index.php/ccm/system/file/upload which could result in an

    KritikCVSS 9,1İstismar yokEPSS %2

    concretecms · concrete cms24 Haz 2022

  • CVE-2026-8134
    37İzleyin

    Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemplate Path Traversal leading to PHP File Inclusion

    KritikCVSS 9,4İstismar yokEPSS %1

    concretecms · concrete cms21 May 2026

  • CVE-2021-40097
    36İzleyin

    An issue was discovered in Concrete CMS through 8.5.5.

    YüksekCVSS 8,8İstismar yokEPSS %3

    concretecms · concrete cms27 Eyl 2021

  • CVE-2021-40102
    36İzleyin

    An issue was discovered in Concrete CMS through 8.5.5.

    KritikCVSS 9,1İstismar yokEPSS %1

    concretecms · concrete cms24 Eyl 2021

  • CVE-2021-22966
    35İzleyin

    Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below.

    YüksekCVSS 8,8İstismar yokEPSS %1

    concretecms · concrete cms19 Kas 2021

  • CVE-2026-3452
    35İzleyin

    Concrete CMS below 9.4.8 is vulnerable to stored deserialization leading to RCE in the Express Entry List block.

    YüksekCVSS 8,9İstismar yokEPSS %1

    concretecms · concrete cms3 Mar 2026

  • CVE-2015-4724
    35İzleyin

    SQL injection vulnerability in Concrete5 5.7.3.1.

    YüksekCVSS 8,8İstismar yokEPSS %1

    concretecms · concrete cms7 Eyl 2017

  • CVE-2026-8135
    35İzleyin

    Concrete CMS 9.5.0 and below is vulnerable to RCE due to insecure deserialization occurring in the ExpressEntryList block controller.

    YüksekCVSS 8,9İstismar yokEPSS %1

    concretecms · concrete cms21 May 2026

  • CVE-2021-22954
    35İzleyin

    A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an attacker to make requests on behalf of other users

    YüksekCVSS 8,8İstismar yokEPSS %1

    concretecms · concrete cms9 Şub 2022

  • CVE-2021-40108
    35İzleyin

    An issue was discovered in Concrete CMS through 8.5.5.

    YüksekCVSS 8,8İstismar yokEPSS %0

    concretecms · concrete cms27 Eyl 2021

  • CVE-2022-43693
    35İzleyin

    Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for users of Concrete w

    YüksekCVSS 8,8İstismar yokEPSS %0

    concretecms · concrete cms14 Kas 2022

  • CVE-2026-81895
    34İzleyin

    Concrete CMS 9.5.2 and below is vulnerable to Stored SQL Injection in Concrete CMS Document Library Block via `fsID[]` in `setMode=any`

    YüksekCVSS 8,5İstismar yokEPSS %1

    concretecms · concrete cms15 Eyl 2026

  • CVE-2026-18110
    34İzleyin

    Concrete CMS 9.0.0 through 9.5.2 is vulnerable to missing authorization in the user selector autocomplete endpoint (/ccm/system/user/autocomplete), allowing an

    YüksekCVSS 8,7Kavram kanıtıEPSS %0

    concretecms · concrete cms15 Eyl 2026

  • CVE-2026-81894
    34İzleyin

    Concrete CMS 9.5.2 and below is vulnerable to Stored DOM-based Cross-site Scripting (XSS) in the Gallery block image Caption field

    YüksekCVSS 8,5İstismar yokEPSS %0

    concretecms · concrete cms15 Eyl 2026

  • CVE-2026-81896
    33İzleyin

    Concrete CMS below version 9.5.3 is vulnerable to Stored XSS in Concrete CMS Form Submissions Report via Unescaped Question Label

    YüksekCVSS 8,4İstismar yokEPSS %0

    concretecms · concrete cms15 Eyl 2026

  • CVE-2021-22970
    30İzleyin

    Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system to be vulnerable to

    YüksekCVSS 7,5İstismar yokEPSS %1

    concretecms · concrete cms19 Kas 2021

  • CVE-2021-40103
    30İzleyin

    An issue was discovered in Concrete CMS through 8.5.5.

    YüksekCVSS 7,5İstismar yokEPSS %1

    concretecms · concrete cms27 Eyl 2021

  • CVE-2021-40104
    30İzleyin

    An issue was discovered in Concrete CMS through 8.5.5.

    YüksekCVSS 7,5İstismar yokEPSS %1

    concretecms · concrete cms27 Eyl 2021

  • CVE-2021-22967
    30İzleyin

    In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to

    YüksekCVSS 7,5İstismar yokEPSS %1

    concretecms · concrete cms19 Kas 2021

  • CVE-2021-22951
    30İzleyin

    Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.

    YüksekCVSS 7,5İstismar yokEPSS %1

    concretecms · concrete cms19 Kas 2021

  • CVE-2026-85385
    30İzleyin

    Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone Field

    YüksekCVSS 7,7İstismar yokEPSS %1

    concretecms · concrete cms16 Eyl 2026