Concretecms

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 173
    Known Exploited: 0
    6
    Critical Level Threats
    38
    High Level Threats
    96
    Medium Level Threats
    14
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-81918

    Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block

    Last Modified: Sep 12, 2026
    Published: Sep 11, 2026

    CVE-2026-81917

    Concrete CMS below 9.5.3 is vulnerable to Stored XSS in the Document Library block file description and tags

    Last Modified: Sep 12, 2026
    Published: Sep 11, 2026

    CVE-2026-68535

    Concrete CMS 9.2.0 to 9.5.2 is vulnerable to Missing authorization in the Concrete CMS Area REST API block-create path letting an editor reference files outside their file-manager permissions

    Last Modified: Sep 12, 2026
    Published: Sep 11, 2026

    CVE-2026-81915

    In Concrete CMS below 9.5.3, Page Type update omits object-level authorization

    Last Modified: Sep 12, 2026
    Published: Sep 11, 2026

    CVE-2026-68526

    Concrete CMS before 9.5.3 is vulnerable to CSRF in the Calendar event duplicate dialog controller

    Last Modified: Sep 12, 2026
    Published: Sep 11, 2026
    Items Per Page
    Concretecms Vulnerabilities & Security CVEs | CVE-DB