← Back

Concretecms

concretecms

154 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Concrete Cms
concrete_cms

CVEs (154)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Concretecms
1Concrete Cms
Jun 17, 2026
Sep 4, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File Manager. It is possible to modify site configuration to upload the PHP file and execute arbitrary co...Show more
Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File Manager. It is possible to modify site configuration to upload the PHP file and execute arbitrary commands.Show less
1Concretecms
1Concrete Cms
Jun 17, 2026
Jul 28, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Concrete5 before 8.5.3 allows Unrestricted Upload of File with Dangerous Type such as a .phar file.
1Concretecms
1Concrete Cms
Jun 17, 2026
Jun 22, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Concrete5 before 8.5.3 does not constrain the sort direction to a valid asc or desc value.
1Concretecms
1Concrete Cms
Nov 21, 2024
Jan 14, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross-Site Scripting (XSS) vulnerability exists in the rcID parameter in Concrete CMS 5.4.1.1 and earlier.
1Concretecms
1Concrete Cms
Nov 21, 2024
Jun 17, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTML data with a SCRIPT element.
1Concretecms
1Concrete Cms
Nov 21, 2024
Jul 9, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network and mapping of the internal network, because of URL functionality on the...Show more
A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network and mapping of the internal network, because of URL functionality on the File Manager page.Show less
1Concretecms
1Concrete Cms
Nov 21, 2024
Feb 26, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. An unauthenticated user can enumerate comments from all blog posts by POSTing requests to /index.php/tools/required/conversations/vi...Show more
An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. An unauthenticated user can enumerate comments from all blog posts by POSTing requests to /index.php/tools/required/conversations/view_ajax with incremental 'cnvID' integers.Show less
1Concretecms
1Concrete Cms
May 13, 2026
Sep 7, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in Concrete5 5.7.3.1.
1Concretecms
1Concrete Cms
May 13, 2026
Sep 7, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Concrete5 5.7.3.1.
1Concretecms
1Concrete Cms
May 13, 2026
Apr 24, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking an admin into viewing a malicious page involving the /tools/required/f...Show more
concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking an admin into viewing a malicious page involving the /tools/required/files/importers/imageeditor?fID=1&imgData= URI. This results in a site-wide denial of service making the site not accessible to any users or any administrators.Show less
1Concretecms
1Concrete Cms
May 13, 2026
Apr 13, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "canonical" URL on installation of concrete5 using the "Advanced Options" settings. Remote attackers ca...Show more
concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "canonical" URL on installation of concrete5 using the "Advanced Options" settings. Remote attackers can make a GET request with any domain name in the Host header; this is stored and allows for arbitrary domains to be set for certain links displayed to subsequent visitors, potentially an XSS vector.Show less
2Concrete5
Concretecms
2Concrete5
Concrete Cms
May 6, 2026
Jan 5, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in concrete5 5.7.2.1, 5.7.2, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gName parameter in single_pages/dashboard/users/group...Show more
Multiple cross-site scripting (XSS) vulnerabilities in concrete5 5.7.2.1, 5.7.2, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gName parameter in single_pages/dashboard/users/groups/bulkupdate.php or (2) instance_id parameter in tools/dashboard/sitemap_drag_request.php.Show less
2Concrete5
Concretecms
2Concrete5
Concrete Cms
May 6, 2026
Jul 28, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in single_pages\download_file.php in concrete5 before 5.6.3 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to index.php/download_file.
2Concrete5
Concretecms
2Concrete5
Concrete Cms
May 6, 2026
Jul 28, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
concrete5 before 5.6.3 allows remote attackers to obtain the installation path via a direct request to (1) system/basics/editor.php, (2) system/view.php, (3) system/environment/file_storage_locations.php, (4) system/mail...Show more
concrete5 before 5.6.3 allows remote attackers to obtain the installation path via a direct request to (1) system/basics/editor.php, (2) system/view.php, (3) system/environment/file_storage_locations.php, (4) system/mail/importers.php, (5) system/mail/method.php, (6) system/permissions/file_types.php, (7) system/permissions/files.php, (8) system/permissions/tasks.php, (9) system/permissions/users.php, (10) system/seo/view.php, (11) view.php, (12) users/attributes.php, (13) scrapbook/view.php, (14) pages/attributes.php, (15) files/attributes.php, or (16) files/search.php in single_pages/dashboard/.Show less