concretecms

3 records · 0 with a public proof-of-concept

Disclosed vulnerabilities where the NVD names concretecms as an affected vendor, highest CVSS first.

  1. MEDIUM 6.5CVE-2026-18426

    Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level edit-permission check on the Express Form block's control-management actions, which relied solely on CSRF token validation. Because the token is bound to the user and action rather than to a specif

    concrete cms

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 6.1CVE-2026-81926

    Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's duplicate-path confirmation dialog. The panel's check endpoint returned the submitted path unmodified in its JSON response, and client-side JavaS

    concrete cms

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 5.4CVE-2026-81927

    Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling. When SVG processing was set to the non-default "Reject files containing potentially harmful elements" mode (concrete.file_manager.images.svg_sanitization.acti

    concrete cms

    AI risk analysis on Exploit-DB.ai →