📦 Concrete Cms

by Concretecms

🔍 What is Concrete Cms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-48648

CRITICAL CVSS 9.8 Nov 17, 2023

Concrete CMS versions before 8.5.13 and 9.x before 9.2.2 create directories with insecure default permissions (0777), allowing unauthorized access. This affects all installations using vulnerable vers...

CVE-2022-21829

CRITICAL CVSS 9.8 Jun 24, 2022

This vulnerability in Concrete CMS allows authenticated high-privilege users to download zip files over unencrypted HTTP connections and execute code from those files, leading to remote code execution...

CVE-2022-30117

CRITICAL CVSS 9.1 Jun 24, 2022

This vulnerability in Concrete CMS allows authenticated attackers to perform directory traversal via the file upload endpoint, potentially leading to arbitrary file deletion. It affects Concrete CMS v...

CVE-2021-40098

CRITICAL CVSS 9.8 Sep 27, 2021

This vulnerability in Concrete CMS allows attackers to perform path traversal attacks through external forms, leading to remote code execution. It affects all Concrete CMS installations through versio...

CVE-2021-40101

HIGH CVSS 7.2 Nov 30, 2021

This vulnerability allows authenticated users in Concrete CMS to change their own or potentially other users' passwords without providing the current password. This affects all Concrete CMS installati...

CVE-2021-22967

HIGH CVSS 7.5 Nov 19, 2021

CVE-2021-22967 is an Insecure Direct Object Reference (IDOR) vulnerability in Concrete CMS that allows unauthenticated users to access restricted files if they have permission to add messages to conve...

CVE-2021-22970

HIGH CVSS 7.5 Nov 19, 2021

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Concrete CMS that allows authenticated users to make requests to internal network resources. Attackers can read files from loca...

CVE-2021-40108

HIGH CVSS 8.8 Sep 27, 2021

This CSRF vulnerability in Concrete CMS allows attackers to trick authenticated users into unknowingly adding malicious calendar events. Attackers can create fake events that could contain malicious l...

CVE-2021-40104

HIGH CVSS 7.5 Sep 27, 2021

This CVE describes an SVG sanitizer bypass vulnerability in Concrete CMS that allows attackers to upload malicious SVG files containing JavaScript. This affects all Concrete CMS installations through ...

CVE-2021-40097

HIGH CVSS 8.8 Sep 27, 2021

This vulnerability allows authenticated attackers in Concrete CMS to perform path traversal attacks, leading to remote code execution by uploading PHP files. It affects all Concrete CMS installations ...

CVE-2021-36766

HIGH CVSS 7.2 Jul 30, 2021

This vulnerability allows attackers to inject malicious PHP objects into Concrete5 applications through deserialization of untrusted data. Attackers can exploit this to execute arbitrary PHP code on t...

CVE-2025-3153

MEDIUM CVSS 6.5 Apr 3, 2025

Concrete CMS versions below 8.5.20 and 9 below 9.4.0RC2 are vulnerable to CSRF and XSS attacks in the Address attribute when a country is not specified. Attackers with address attribute editing permis...

CVE-2025-0660

MEDIUM CVSS 4.8 Mar 10, 2025

Concrete CMS versions 9.0.0 through 9.3.9 contain a stored cross-site scripting (XSS) vulnerability in the 'Add Folder' functionality. A rogue administrator can inject malicious JavaScript as folder n...

CVE-2024-8291

MEDIUM CVSS 4.8 Sep 25, 2024

This vulnerability allows a rogue administrator in Concrete CMS to inject malicious JavaScript code through the Image Editor Background Color feature, creating stored cross-site scripting (XSS) attack...

CVE-2024-7398

MEDIUM CVSS 5.4 Sep 25, 2024

Concrete CMS versions 9 through 9.3.3 and versions below 8.5.19 contain a stored cross-site scripting (XSS) vulnerability in the calendar event addition feature. Users or groups with permission to cre...

CVE-2024-8660

MEDIUM CVSS 4.8 Sep 17, 2024

Concrete CMS versions 9.0.0 through 9.3.3 have a stored cross-site scripting (XSS) vulnerability in the Top Navigator Bar block. A rogue administrator can inject malicious JavaScript that executes whe...

CVE-2024-7394

MEDIUM CVSS 4.8 Aug 8, 2024

Concrete CMS versions 9 through 9.3.2 and below 8.5.18 contain a stored cross-site scripting (XSS) vulnerability in the getAttributeSetName() function. A rogue administrator can inject malicious JavaS...