CVE-2026-81907Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) vin Express delete_entries allowing mass deletion of all entity records Exploitation status Not confirmed Fix YesAffected product C Concrete CMS Published 09/11/2026 Severity Medium CVE-2026-81918Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block Exploitation status Not confirmed Fix YesAffected product C Concrete CMS Published 09/11/2026 Severity Medium CVE-2026-81917Concrete CMS below 9.5.3 is vulnerable to Stored XSS in the Document Library block file description and tags Exploitation status Not confirmed Fix YesAffected product C Concrete CMS Published 09/11/2026 Severity Medium CVE-2026-68535Concrete CMS 9.2.0 to 9.5.2 is vulnerable to Missing authorization in the Concrete CMS Area REST API block-create path letting an editor reference files outside their file-manager permissions Exploitation status Not confirmed Fix YesAffected product C Concrete CMS Published 09/11/2026 Severity Medium CVE-2026-81916Incorrect Authorization in the Concrete CMS Express Entries Dashboard below version 9.5.3 Allows Entry Creation in an Unauthorized Object Exploitation status Not confirmed Fix YesAffected product C Concrete CMS Published 09/11/2026 Severity Medium CVE-2026-81915In Concrete CMS below 9.5.3, Page Type update omits object-level authorization Exploitation status Not confirmed Fix YesAffected product C Concrete CMS Published 09/11/2026 Severity Medium CVE-2026-68526Concrete CMS before 9.5.3 is vulnerable to CSRF in the Calendar event duplicate dialog controller Exploitation status Not confirmed Fix Not confirmed Affected product C Concrete CMS Published 09/11/2026 Severity Medium CVE-2026-81913Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 09/11/2026 Severity Medium CVE-2026-81912Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 09/11/2026 Severity Medium CVE-2026-81911Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot save_template via Unescaped Summary Description Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 09/11/2026 Severity Medium CVE-2026-81910Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 09/11/2026 Severity Medium CVE-2026-81909Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block alias route, allowing an authenticated editor to disclose and force-delete arbitrary blocks Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 09/11/2026 Severity Medium CVE-2026-68528Concrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Block via Unescaped Remote Feed Item title Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 09/11/2026 Severity Medium CVE-2026-18122Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 09/11/2026 Severity Medium CVE-2026-81908Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows Authenticated Users to Enumerate All Groups Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 09/11/2026 Severity Medium CVE-2026-81906[UNREVIEWED] OAuth Callback Login Bypasses Deactivated-Account Checks Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 09/10/2026 Severity Medium CVE-2026-81905Concrete CMS below 9.5.3 does not enforce validation-hash type on redemption, allowing a hash issued for one purpose to be redeemed for another. Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 09/10/2026 Severity Medium CVE-2026-18121Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) in the Calendar block's frontend event dialog (/ccm/calendar/view_event/{bID}/{occurrence_id}). Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 09/10/2026 Severity Medium CVE-2026-84432Concrete CMS 9 through 9.5.2 is vulnerable to CSRFin the Boards custom slot dialog controller Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 09/10/2026 Severity Medium CVE-2026-68527Concrete CMS 8.3.0 through 9.5.2 is vulnerable to an authorization bypass through user-controlled key (cross-calendar IDOR) in the Calendar event edit dialog Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 09/10/2026 Severity Medium CVE-2026-81904Concrete CMS before 9.5.3 is vulnerable to Missing Authorization in Stack/Container Sub-Block Asset Registration Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 09/08/2026 Severity Medium CVE-2026-10721Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and Search components Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 06/10/2026 Severity High CVE-2026-7888Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 06/03/2026 Severity High CVE-2026-8353Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in atomik theme Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/22/2026 Severity Low CVE-2026-8347Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialog Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/22/2026 Severity Low CVE-2026-8340Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/22/2026 Severity Low CVE-2026-8139Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Low CVE-2026-7890Concrete CMS 9.5.0 is vulnerable to SSRF via RSS Displayer Block Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Low CVE-2026-8409Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Low CVE-2026-8410Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Low CVE-2026-8411Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Low CVE-2026-8412Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Low CVE-2026-8413Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Low CVE-2026-8414Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Low CVE-2026-8415Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Low CVE-2026-8416Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id) Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Low CVE-2026-8427Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id) Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Low CVE-2026-8432Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star() Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Low CVE-2026-8433Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan() Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Low CVE-2026-8434Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple() Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Low CVE-2026-8435Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion() Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Low CVE-2026-7887For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Low CVE-2026-7886Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Low CVE-2026-7882Concrete CMS 9.5.0 and below is vulnerable to CSRF via the DeleteFile controller Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Low CVE-2026-8327Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass. Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Medium CVE-2026-8245Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Medium CVE-2026-8337Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys when sites are running concurrent public surveys and private surveys Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Medium CVE-2026-8240Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure in Backend\SummaryTemplate Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Medium CVE-2026-7881Concrete CMS 9.5.0 and below is vulnerable to IDOR in the Express Entry Detail block Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Medium CVE-2026-7879Concrete CMS 9.5.0 and below is vulnerable to File Download Authorization Bypass in submit_password() Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Medium CVE-2026-8238Concrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/message_page' allowing unauthenticated read of any conversation message Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Medium CVE-2026-8237Concrete CMS 9.5.0 and below is vulnerable to IDOR in the`/ccm/frontend/conversations/message_detail` endpoint Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Medium CVE-2026-8239Concrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/get_rating' Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Medium CVE-2026-8236Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate for endpoint /ccm/system/dialogs/file/usage/{fID} Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Medium CVE-2026-8205Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in Calendar Block since action_get_events does not check canView on the calendar Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Medium CVE-2026-8204Concrete CMS 9.5.0 and below is vulnerable to Authorization Bypass in the Calendar Event Frontend Dialog Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Medium CVE-2026-6826Concrete 9.5.0 and below has file usage disclosure via missing permission check in Usage controller Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Medium CVE-2026-8203Concrete CMS 9.5.0 and below has Stored XSS on the height parameter Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity High CVE-2026-8197Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration name Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity High CVE-2026-8350Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to privilege escalation to Administrative Group Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity High CVE-2026-8421Concrete CMS 9.5.0 and below is vulnerable to CSRF on install_package() with conditional token bypass leading to RCE Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity High CVE-2026-8428CSRF token is not validated in the core CMS update controller for Concrete CMS 9.5.0 and below Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity High CVE-2026-8426Concrete CMS 9.5.0 and below is vulnerable to CSRF on prepare_remote_upgrade() leading to one-request RCE via package overwrite Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity High CVE-2026-8140Concrete CMS 9.5.0 and below is vulnerable to CSRF on download() in the package install controller Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity High CVE-2026-8417Concrete CMS 9.5.0 and below is vulnerable to CSRF in do_update() in the package update controller Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity High CVE-2026-8135Concrete CMS 9.5.0 and below is vulnerable to RCE due to insecure deserialization occurring in the ExpressEntryList block controller. Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity High CVE-2026-8134Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemplate Path Traversal leading to PHP File Inclusion Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 05/21/2026 Severity Critical CVE-2026-2994Concrete CMS below 9.4.8 is vulnerable to CSRF by a Rogue Admin using the Anti-Spam Allowlist Group Exploitation status Not known exploited Fix Not confirmed Affected product Not confirmed Published 03/04/2026 Severity Low CVE-2026-3240Concrete CMS below 9.4.8 is vulnerable to Stored XSS via Legacy form Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 03/04/2026 Severity Medium CVE-2026-3241Concrete CMS below version 9.4.8 is vulnerable to a stored cross-site scripting (XSS) in the "Legacy Form" block. Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 03/04/2026 Severity Medium CVE-2026-3242Concrete CMS below 9.4.8 is vulnerable to Stored XSS in the Switch Language block Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 03/04/2026 Severity Medium CVE-2026-3244Concrete CMS below version 9.4.8 is vulnerable to Stored XSS in Search Results via Page Names Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 03/04/2026 Severity Medium CVE-2026-3452Concrete CMS below 9.4.8 is vulnerable to stored deserialization leading to RCE in the Express Entry List block. Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 03/04/2026 Severity High CVE-2025-8571Concrete CMS 9 through 9.4.2 and below 8.5.21 is vulnerable to Reflected Cross-Site Scripting (XSS) in Conversation Messages Dashboard Page Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 08/05/2025 Severity Medium CVE-2025-8573Concrete CMS 9 through 9.4.2 is vulnerable to Stored XSS from Home Folder on Members Dashboard page Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 08/05/2025 Severity Low CVE-2025-3153Concrete CMS version 9 below 9.4.0RC2 and versions below 8.5.20 - CSRF and XSS in Concrete CMS Custom Address attribute Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 04/03/2025 Severity Medium CVE-2025-0660Stored XSS in Folder Function by Rogue Admin Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 03/10/2025 Severity Medium CVE-2024-7398Concrete CMS Stored XSS Vulnerability in Calendar Event Addition Feature Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 09/24/2024 Severity Medium CVE-2024-8291Concrete CMS Stored XSS in Image Editor Background Color Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 09/24/2024 Severity Medium CVE-2024-8660Stored XSS in the "Top Navigator Bar" block Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 09/17/2024 Severity Medium CVE-2024-8661Concrete CMS version 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" block Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 09/16/2024 Severity Medium CVE-2024-4350Concrete CMS version 9 below 9.3.3 and below 8.5.18 are vulnerable to Stored XSS in RSS Displayer Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 08/09/2024 Severity Medium CVE-2024-7512Concrete CMS Stored XSS in Board instances Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 08/09/2024 Severity Medium CVE-2024-7394Concrete CMS version 9.0.0 through 9.3.2 and below 8.5.18 - Stored XSS in getAttributeSetName() Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 08/08/2024 Severity Medium CVE-2024-4353Stored XSS in Generate Board Name Input Field Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 08/01/2024 Severity Medium CVE-2024-3181Concrete CMS version 9 prior to 9.2.8 and previous versions prior to 8.5.16 are vulnerable to Stored XSS in the Search Field. Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 04/03/2024 Severity Low CVE-2024-3180Concrete CMS version 9 below 9.2.8 and previous versions below 8.5.16 is vulnerable to Stored XSS in blocks of type file Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 04/03/2024 Severity Low CVE-2024-3179Concrete CMS version 9 before 9.2.8 and previous versions before 8.5.16 are vulnerable to Stored XSS in the Custom Class page Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 04/03/2024 Severity Low CVE-2024-3178Concrete CMS versions 9 below 9.2.8 and versions below 8.5.16 are vulnerable to Cross-site Scripting (XSS) in the Advanced File Search Filter Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 04/03/2024 Severity Low CVE-2024-2753Concrete CMS version 9 below 9.2.8 and below 8.5.16 is vulnerable to stored XSS on the calendar color settings screen Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 04/03/2024 Severity Low CVE-2024-2179Concrete CMS version 9 before 9.2.7 is vulnerable to Stored XSS via the Name field of a Group type Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 03/05/2024 Severity Low CVE-2024-1245Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributes Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 02/09/2024 Severity Low CVE-2024-1246Concrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import Feature Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 02/09/2024 Severity Low CVE-2024-1247Concrete CMS version 9 before 9.2.5 vulnerable to stored XSS via the Role Name field Exploitation status Not known exploited Fix YesAffected product C Concrete CMS Published 02/09/2024 Severity Low CVE-2011-3183Exploitation status Not confirmed Fix Not confirmed Affected product C Concrete CMS Published 01/14/2020 Severity Unknown