PatchSiren

Concrete CMS CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Concrete CMS CVE published 2026-09-14

CVE-2026-81903

A Cross-Site Scripting (XSS) vulnerability exists in Concrete CMS versions 9.0.0 to 9.5.2. A user with access to the Page Containers dashboard can store a crafted icon value that, when viewed by another editor or administrator, can execute script in their authenticated session, potentially leading to session token theft and unauthorized dashboard actions.

HIGH Concrete CMS CVE published 2026-09-14

CVE-2026-81902

A remote attacker could craft a request that, when loaded by an authenticated user holding edit permission on the target page, deleted every block on that page's current version; blocks not aliased to another page or scrapbook entry were also removed from the global Blocks table and their block-type data table, permanently destroying the content. The vulnerability allows for the deletion of blocks without [truncated]

HIGH Concrete CMS CVE published 2026-09-14

CVE-2026-81901

A vulnerability in Concrete CMS 9.2.0 through 9.5.2 allows users with content-editing rights to alter page properties, template, and type through the REST API, and persist JavaScript in the head element of every page, which executes in the browser of every visitor. This could lead to unauthorized changes and potential XSS attacks on visitors, including higher-privileged reviewers. The vulnerability is par [truncated]

HIGH Concrete CMS CVE published 2026-09-14

CVE-2026-18119

CVE-2026-18119 is a stored cross-site scripting vulnerability in Concrete CMS versions below 9.5.3. The vulnerability allows an editor-level user to execute script in an administrator's session and escalate privileges. The CVSS v4.0 score is 7.0. This vulnerability is particularly concerning because it can be exploited through the Block Design dialog, a feature commonly used by editor-level users. The vul [truncated]

MEDIUM Concrete CMS CVE published 2026-09-11

CVE-2026-81918

A vulnerability in Concrete CMS below version 9.5.3 allows for Stored XSS via the Date Format field in the Page Attribute Display block. An authenticated user with edit_page_contents permissions can store a payload that executes in the browser of any visitor who views a page where the block is configured to display a date-type attribute. The vulnerability requires attention from Concrete CMS administrator [truncated]

MEDIUM Concrete CMS CVE published 2026-09-11

CVE-2026-81917

A Cross-Site Scripting (XSS) vulnerability exists in Concrete CMS versions below 9.5.3. This vulnerability allows a user with permission to edit file properties to store a script payload in the file description and tags fields. When a page displaying the Document Library block is visited, the script executes in the browser of the visitor, potentially leading to theft of session data or actions performed i [truncated]

MEDIUM Concrete CMS CVE published 2026-09-11

CVE-2026-81916

A vulnerability in Concrete CMS before version 9.5.3 allows users with permission to add entries to one Express object to create entries in a different Express object outside their authorization scope. This could potentially pollute protected datasets, trigger workflows, or inject content into administrative processes. The vulnerability has a CVSS v4.0 score of 5.1 and is considered medium severity.

MEDIUM Concrete CMS CVE published 2026-09-11

CVE-2026-81915

CVE-2026-81915 is a medium-severity vulnerability in Concrete CMS that allows a signed-in dashboard user to modify Page Types outside their assigned authorization boundary. The vulnerability has a CVSS v4.0 score of 5.1 and is caused by a lack of object-level authorization when updating Page Types. This could lead to unauthorized modifications of Page Types, emphasizing the need for defenders to verify an [truncated]

MEDIUM Concrete CMS CVE published 2026-09-11

CVE-2026-81913

CVE-2026-81913 is a medium-severity vulnerability in Concrete CMS versions 9.5.0 through 9.5.2, allowing open redirects via the rcURL parameter. This vulnerability facilitates phishing and credential theft. The vulnerability has a CVSS v4.0 score of 5.3. Defenders and administrators of Concrete CMS versions 9.5.0 through 9.5.2 should assess exposure and prioritize mitigation, as open redirect vulnerabilit [truncated]

MEDIUM Concrete CMS CVE published 2026-09-11

CVE-2026-81912

A Cross-Site Request Forgery vulnerability exists in Concrete CMS before version 9.5.3, specifically in the Move Multiple Groups feature. An authenticated user could be tricked into performing unintended actions on group nodes without their consent, potentially altering authorization settings for group members. The vulnerability allows an attacker to move selected group tree nodes without validating an ac [truncated]

MEDIUM Concrete CMS CVE published 2026-09-11

CVE-2026-81911

A vulnerability in Concrete CMS versions 9.0.0 to 9.5.2 allows for Stored XSS in the Board Custom Slot dialog. An attacker with permission to edit board contents can store a forged summary object with a JavaScript-bearing HTML payload, which executes in the browser of users who view the affected board slot. This can enable session or action takeover and escalation toward an administrator. The vulnerabilit [truncated]

MEDIUM Concrete CMS CVE published 2026-09-11

CVE-2026-68526

A vulnerability in Concrete CMS before version 9.5.3 allows an authenticated user with add-event permission to create duplicate CalendarEvents and CalendarEventVersions records due to the lack of validation of an anti-CSRF token in the Calendar event duplicate dialog controller. This issue could impact system performance or data integrity. The vulnerability has been assigned a CVSS v4.0 score of 5.3 with [truncated]

MEDIUM Concrete CMS CVE published 2026-09-11

CVE-2026-81910

A Server-Side Template Injection (SSTI) vulnerability exists in Concrete CMS versions 9 through 9.5.2, specifically in the Theme Customizer. This allows users with Theme Customization permissions to inject arbitrary LESS directives by submitting unvalidated style values. The vulnerability can be exploited to read arbitrary files on the server, access internal network resources, and expose sensitive applic [truncated]

MEDIUM Concrete CMS CVE published 2026-09-11

CVE-2026-81909

A Missing Authorization vulnerability in Concrete CMS 9 through 9.5.2 allows a user with area-scoped add_block_to_area delegation on their own page to duplicate and delete arbitrary block content. This discloses the original block's content and destroys site content. The vulnerability stems from the block alias route not verifying if the referenced block is genuinely orphaned on the target page or if the [truncated]

MEDIUM Concrete CMS CVE published 2026-09-11

CVE-2026-81908

A missing authorization vulnerability in Concrete CMS 9.2.0 to 9.5.2 allows an authenticated user with the groups:read scope to retrieve all groups on the site, regardless of view permissions, via the REST API Groups list endpoint. This issue discloses the organization's group structure, roles, and access hierarchy. Defenders should assess exposure and verify access controls, especially for publicly acces [truncated]

MEDIUM Concrete CMS CVE published 2026-09-11

CVE-2026-68528

A stored cross-site scripting vulnerability exists in Concrete CMS RSS Displayer block versions below 9.5.3. An attacker controlling a title in a syndicated feed could execute script in the site origin for any visitor, including administrators, without an account on that site. The vulnerability allows for the execution of arbitrary script, potentially leading to unauthorized actions by attackers on behalf [truncated]

MEDIUM Concrete CMS CVE published 2026-09-11

CVE-2026-18122

A Missing Authorization vulnerability in Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint allows an OAuth token with read scope for an Express entity to enumerate entries that its user context lacks permission to view, disclosing public identifiers, URLs, labels, dates, and attribute or associated-entry data. This vulnerability impacts Concrete CMS instances with exposed Express REST API list en [truncated]

MEDIUM Concrete CMS CVE published 2026-09-11

CVE-2026-81906

A vulnerability in Concrete CMS OAuth callback login path prior to version 9.5.3 allows a deactivated or unvalidated user with an existing OAuth binding to complete authentication and receive a fully authenticated session. The login is recorded and login events are dispatched. This issue has a CVSS v4.0 score of 6.3. Affected product deployments should be identified and verified for exposure. Defenders sh [truncated]

MEDIUM Concrete CMS CVE published 2026-09-11

CVE-2026-81905

A vulnerability in Concrete CMS allows an attacker to redeem a hash issued for one purpose (e.g., email validation, password reset, or persistent login) for another purpose due to the redemption path resolving a hash by value alone without verifying its type. This issue requires the attacker to first obtain a valid hash through a separate channel, such as email interception or log exposure.

MEDIUM Concrete CMS CVE published 2026-09-11

CVE-2026-18121

An authorization bypass vulnerability exists in Concrete CMS versions 9.5.2 and below, allowing unauthenticated visitors to disclose event metadata from calendars they are not permitted to view. The vulnerability is due to the frontend calendar lightbox endpoint not verifying caller permissions. A CVSS v4.0 score of 6.3 was given with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N.

HIGH Concrete CMS CVE published 2026-06-10

CVE-2026-10721

CVE-2026-10721 is a high-severity vulnerability in Concrete CMS versions below 9.5.2. The vulnerability allows for PHP object injection via unserialize() calls in the Permission, Cache, and Search components. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious serialized payload has been placed in the database. The vulnerability has a CVSS score of 8.4 and is consider [truncated]

LOW Concrete CMS CVE published 2026-05-22

CVE-2026-8353

A Stored XSS vulnerability exists in Concrete CMS versions 9.0 to 9.5.0, specifically in the Atomik theme, allowing a rogue editor to inject arbitrary JavaScript that executes in the context of any authenticated user visiting affected account pages. This can lead to session hijacking, credential theft, malicious actions performed on behalf of users, and potential privilege escalation. The vulnerability ha [truncated]

LOW Concrete CMS CVE published 2026-05-22

CVE-2026-8347

A low-severity vulnerability was found in Concrete CMS 9.5.0 and below. The issue is an IDOR (Insecure Direct Object Reference) vulnerability combined with wrong authorization levels in the Express association Reorder dialog. This can lead to Cross-entity state tampering with view-only permission on one entry. To be affected, a website must be using Express and relying on Express entity ordering. The Conc [truncated]

LOW Concrete CMS CVE published 2026-05-22

CVE-2026-8340

Concrete CMS versions 9.5.0 and below contain a Cross-Site Request Forgery (CSRF) vulnerability in the file approval workflow. An attacker can craft a malicious request that, when triggered by an authenticated user with edit_file_contents permission, causes the victim to unknowingly publish a previously-uploaded file version. This enables two attack scenarios: downgrading a file to an older version (poten [truncated]

LOW Concrete CMS CVE published 2026-05-21

CVE-2026-8435

CVE-2026-8435 describes a cross-site request forgery issue in Concrete CMS 9 before 9.5.0 affecting the file version approval controller action concrete/controllers/backend/file approveVersion(). NVD assigns a low CVSS v4.0 score of 2.3 and lists CWE-352 along with CWE-1275. The issue was publicly recorded on 2026-05-21, and the supplied vendor reference points to Concrete CMS 9.5.0 release notes as the r [truncated]

LOW Concrete CMS CVE published 2026-05-21

CVE-2026-8433

CVE-2026-8433 is a low-severity CSRF issue affecting Concrete CMS 9 before 9.5.0. The vulnerable path is concrete/controllers/backend/file rescan(), and the vendor-assigned CVSS v4.0 score is 2.3 with a vector indicating network reachability, required user interaction, and limited integrity impact. The issue was publicly recorded on 2026-05-21, and the supplied corpus identifies Yonatan Drori (Tenzai) as [truncated]

LOW Concrete CMS CVE published 2026-05-21

CVE-2026-8432

CVE-2026-8432 is a Cross-Site Request Forgery (CSRF) issue affecting Concrete CMS 9 before 9.5.0, specifically in concrete/controllers/backend/file star(). The vulnerability was assigned a CVSS v4.0 score of 2.3 (LOW) with a vector indicating network reachability, required user interaction, and low integrity impact. The practical takeaway is straightforward: organizations running affected Concrete CMS 9 d [truncated]

LOW Concrete CMS CVE published 2026-05-21

CVE-2026-8427

CVE-2026-8427 is a low-severity Cross-Site Request Forgery issue in Concrete CMS 9 before 9.5.0. The vulnerable path is concrete/controllers/backend/file removeFavoriteFolder($id), and the Concrete CMS security team assigned CVSS v4.0 2.3 (AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N). The issue was publicly recorded on 2026-05-21 and reported by Yonatan Drori (Tenzai).

LOW Concrete CMS CVE published 2026-05-21

CVE-2026-8416

CVE-2026-8416 is a low-severity CSRF issue in Concrete CMS 9 before 9.5.0. The affected backend controller action can be triggered in a way that may cause an authenticated user’s browser to perform an unintended favorite-folder change. The issue was reported by Yonatan Drori (Tenzai) and assigned a CVSS v4.0 score of 2.3.

LOW Concrete CMS CVE published 2026-05-21

CVE-2026-8415

CVE-2026-8415 is a low-severity CSRF issue in Concrete CMS 9 versions before 9.5.0. The affected path is concrete/controllers/dialog/express/association/reorder, and the vendor states the fix is available in 9.5.0. NVD and the Concrete CMS release notes both point to this issue, which was reported by Yonatan Drori (Tenzai).