LIVE · cybersecurity feed
Live wire
vendor

Concretecms

20 CVEs published in the last four months. Exploited flaws first.

Critical0
High19
Medium1
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-84348.8highconcrete cmsConcrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file107d ago
CVE-2026-84278.8highconcrete cmsConcrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file107d ago
CVE-2026-84328.8highconcrete cmsConcrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file107d ago
CVE-2026-84338.8highconcrete cmsConcrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file107d ago
CVE-2026-83508.8highconcrete cmsConcrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead 107d ago
CVE-2026-84178.8highconcrete cmsConcrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/107d ago
CVE-2026-84218.8highconcrete cmsConcrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/107d ago
CVE-2026-84268.8highconcrete cmsConcrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/107d ago
CVE-2026-84288.8highconcrete cmsConcrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update')107d ago
CVE-2026-84098.8highconcrete cmsConcrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/107d ago
CVE-2026-84108.8highconcrete cmsConcrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/107d ago
CVE-2026-84118.8highconcrete cmsConcrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/107d ago
CVE-2026-84128.8highconcrete cmsConcrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/107d ago
CVE-2026-84138.8highconcrete cmsConcrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/107d ago
CVE-2026-84148.8highconcrete cmsConcrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event107d ago
CVE-2026-84158.8highconcrete cmsConcrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/expre107d ago
CVE-2026-84168.8highconcrete cmsConcrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file107d ago
CVE-2026-81347.2highconcrete cmsConcrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustom107d ago
CVE-2026-81357.2highconcrete cmsConcrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in th107d ago
CVE-2026-306626.5mediumconcrete cmsConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component.165d ago

Filter the full tracker by Concretecms