SecAlerts
C

Concrete CMS

Security Risk Profile

40
/100
medium

Security Risk Score

Comprehensive risk assessment based on 52 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 10, 2025 to present

52
Total CVEs
12
Critical+High
0
Exploited
12
Unpatched

Threat Assessment

Avg CVSS
4.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
12
Critical/High
Risk Level
40/100
medium
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
1
High
11
Medium
18
Low
21

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
46

Age Distribution

Common Weaknesses (CWE)

1
CSRF
21
2
XSS
9
3
Input Validation
2
4
SSRF
1
5
Infoleak
1

Most Affected Products

1. ConcreteCMS Concrete CMS52
2. Concrete CMS Concrete CMS40
3. Concrete CMS Concrete CMS 912
4. composer/concrete5/concrete56

Recent Vulnerabilities

See more →
CVE-2026-81904
unknown

Missing Authorization in Stack/Container Sub-Block Asset Registration

Sep 8, 2026🔧 No Patch
CVE-2026-10721
CVSS 8.4high

Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and Search components

Jun 10, 2026🔧 No Patch
CVE-2026-7888
CVSS 8.4high

Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction.

Jun 3, 2026🔧 No Patch
CVE-2026-8353
CVSS 2.1EPSS 0%low

Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in atomik theme

May 22, 2026🔧 No Patch
CVE-2026-8347
CVSS 2.3EPSS 0%low

Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialog

May 22, 2026🔧 No Patch
CVE-2026-8340
CVSS 2.3EPSS 0%low

Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion

May 22, 2026🔧 No Patch
CVE-2026-8139
CVSS 2.0EPSS 0%low

Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName

May 21, 2026🔧 No Patch
CVE-2026-7890
CVSS 2.1EPSS 0%low

Concrete CMS 9.5.0 is vulnerable to SSRF via RSS Displayer Block

May 21, 2026🔧 No Patch
CVE-2026-8409
CVSS 2.3EPSS 0%low

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete

May 21, 2026🔧 No Patch
CVE-2026-8410
CVSS 2.3EPSS 0%low

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete

May 21, 2026🔧 No Patch

Monitor Concrete CMS in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.