SecAlerts
C

ConcreteCMS

Security Risk Profile

38
/100
low

Security Risk Score

Comprehensive risk assessment based on 164 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from July 28, 2014 to present

164
Total CVEs
36
Critical+High
1
Exploited
31
Unpatched

Threat Assessment

Avg CVSS
5.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
31
Critical/High
Risk Level
38/100
low
⚠️ 1 Active Exploits

Severity Distribution

Critical
8
High
28
Medium
104
Low
24

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
75

Age Distribution

Common Weaknesses (CWE)

1
XSS
78
2
CSRF
32
3
Input Validation
16
4
Code Injection
9
5
SSRF
7

Most Affected Products

1. ConcreteCMS Concrete CMS155
2. composer/concrete5/concrete574
3. ConcreteCMS Concrete Cms48
4. Concrete CMS Concrete CMS37
5. concrete5 concrete515

Recent Vulnerabilities

See more →
CVE-2026-8353
CVSS 2.1EPSS 0%low

Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in atomik theme

May 22, 2026🔧 No Patch
CVE-2026-8347
CVSS 2.3EPSS 0%low

Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialog

May 22, 2026🔧 No Patch
CVE-2026-8340
CVSS 2.3EPSS 0%low

Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion

May 22, 2026🔧 No Patch
CVE-2026-8139
CVSS 2.0EPSS 0%low

Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName

May 21, 2026🔧 No Patch
CVE-2026-7890
CVSS 2.1EPSS 0%low

Concrete CMS 9.5.0 is vulnerable to SSRF via RSS Displayer Block

May 21, 2026🔧 No Patch
CVE-2026-8409
CVSS 2.3EPSS 0%low

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete

May 21, 2026🔧 No Patch
CVE-2026-8410
CVSS 2.3EPSS 0%low

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete

May 21, 2026🔧 No Patch
CVE-2026-8411
CVSS 2.3EPSS 0%low

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete

May 21, 2026🔧 No Patch
CVE-2026-8412
CVSS 2.3EPSS 0%low

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache

May 21, 2026🔧 No Patch
CVE-2026-8413
CVSS 2.3EPSS 0%low

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design

May 21, 2026🔧 No Patch

Monitor ConcreteCMS in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.