| CVE-2026-8434 | 8.8 | high | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file | 107d ago |
| CVE-2026-8433 | 8.8 | high | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file | 107d ago |
| CVE-2026-8432 | 8.8 | high | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file | 107d ago |
| CVE-2026-8427 | 8.8 | high | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file | 107d ago |
| CVE-2026-8416 | 8.8 | high | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file | 107d ago |
| CVE-2026-8415 | 8.8 | high | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/expre | 107d ago |
| CVE-2026-8414 | 8.8 | high | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event | 107d ago |
| CVE-2026-8413 | 8.8 | high | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/ | 107d ago |
| CVE-2026-8412 | 8.8 | high | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/ | 107d ago |
| CVE-2026-8411 | 8.8 | high | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/ | 107d ago |
| CVE-2026-8410 | 8.8 | high | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/ | 107d ago |
| CVE-2026-8409 | 8.8 | high | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/ | 107d ago |
| CVE-2026-8428 | 8.8 | high | concretecms / concrete cms | Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update') | 107d ago |
| CVE-2026-8426 | 8.8 | high | concretecms / concrete cms | Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/ | 107d ago |
| CVE-2026-8421 | 8.8 | high | concretecms / concrete cms | Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/ | 107d ago |
| CVE-2026-8417 | 8.8 | high | concretecms / concrete cms | Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/ | 107d ago |
| CVE-2026-8350 | 8.8 | high | concretecms / concrete cms | Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead | 107d ago |
| CVE-2026-8135 | 7.2 | high | concretecms / concrete cms | Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in th | 107d ago |
| CVE-2026-8134 | 7.2 | high | concretecms / concrete cms | Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustom | 107d ago |
| CVE-2026-30662 | 6.5 | medium | concretecms / concrete cms | ConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. | 165d ago |