Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
221 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.26% | — | Concretecms Concrete CMS | 21/5/2026 | 23/7/2026 | Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/single_page/dashboard/extend/install.php. An attacker who can cause an authenticated administrator to visit a crafted page, and who has placed or caused a package to be present under… | |
| Analizada | Alta (7.5) | 0.19% | — | Concretecms Concrete CMS | 21/5/2026 | 23/7/2026 | Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/do_update/<pkgHandle>. The do_update() method in concrete/controllers/single_page/dashboard/extend/update.php checks only canInstallPackages() before executing upgradeCoreData() and upgrade() on the named… | |
| Analizada | Alta (7.5) | 0.47% | — | Concretecms Concrete CMS | 21/5/2026 | 23/7/2026 | Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to privilege escalation to Administrative Group. Any authenticated user with access to the bulk user assignment dashboard page can add any user email to any group and can remove legitimate admins. The… | |
| Analizada | Media (6.3) | 0.35% | — | Concretecms Concrete CMS | 21/5/2026 | 23/7/2026 | Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calendar Block since action_get_events does not check canView on the calendar which results in restricted event details being disclosed. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with vector… | |
| Analizada | Media (6.3) | 0.35% | — | Concretecms Concrete CMS | 21/5/2026 | 23/7/2026 | Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend Dialog which can allow cross-calendar data disclosure. A public calendar block can be used as a pivot point to access private calendar data. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3… | |
| Analizada | Alta (7.3) | 0.21% | — | Concretecms Concrete CMS | 21/5/2026 | 23/7/2026 | Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validate or sanitize $height. Any user with editor privileges can inject malicious JavaScript that executes in the context of any visitor's browser, potentially leading to session hijacking, credential theft, or other… | |
| Analizada | Alta (7.3) | 0.25% | — | Concretecms Concrete CMS | 21/5/2026 | 23/7/2026 | Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration name. The OAuth authorize template renders the integration name (admin-controlled) through Concrete's t() translation helper as a sprintf-style format. The <strong>...</strong> wrap is built by PHP string interpolation before t() runs, so… | |
| Analizada | Alta (7.5) | 0.16% | — | Concretecms Concrete CMS | 21/5/2026 | 23/7/2026 | Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/install/download/<remoteId>. The download() method in concrete/controllers/single_page/dashboard/extend/install.php checks only the canInstallPackages() permission before fetching a remote marketplace package… | |
| Analizada | Alta (8.9) | 0.74% | — | Concretecms Concrete CMS | 21/5/2026 | 23/7/2026 | Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the ExpressEntryList block controller. An rogue administrator with privileges to add blocks to an area can bypass the intended protection mechanism (_fromCIF === true), which normally restricts malicious… | |
| Analizada | Crítica (9.4) | 1.1% | — | Concretecms Concrete CMS | 21/5/2026 | 23/7/2026 | Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue administrator with composer form editing rights can exploit this to include arbitrary readable files on the server.… | |
| Analizada | Media (6.9) | 1.3% | 💥 Exploit | Concretecms Concrete CMS | 21/5/2026 | 23/7/2026 | Concrete CMS 9.5.0 and below is vulnerable to unauthenticated file usage disclosure via missing permission check in the usage controller. Any unauthenticated visitor can request /ccm/system/dialogs/file/usage/{fID} with any file ID and receive a list of every page that references that file, including page IDs,… | |
| Modificada | Media (6.5) | 0.44% | — | Concretecms Concrete CMS | 24/3/2026 | 17/6/2026 | ConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. The 'download' method in 'concrete/controllers/backend/file.php' improperly manages memory when creating zip archives. It uses 'ZipArchive::addFromString' combined with 'file_get_contents', which loads the entire content… | |
| Analizada | Media (4.8) | 0.28% | — | Concretecms Concrete CMS | 4/3/2026 | 17/6/2026 | In Concrete CMS below version 9.4.8, a rogue administrator can add stored XSS via the Switch Language block. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 4.8 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks M3dium for reporting. | |
| Analizada | Media (4.8) | 0.28% | — | Concretecms Concrete CMS | 4/3/2026 | 17/6/2026 | In Concrete CMS below version 9.4.8, a stored cross-site scripting (XSS) vulnerability exists in the "Legacy Form" block. An authenticated user with permissions to create or edit forms (e.g., a rogue administrator) can inject a persistent JavaScript payload into the options of a multiple-choice question (Checkbox… | |
| Analizada | Media (4.8) | 0.28% | — | Concretecms Concrete CMS | 4/3/2026 | 17/6/2026 | In Concrete CMS below version 9.4.8, a user with permission to edit a page with element Legacy form can perform a stored XSS attack towards high-privilege accounts via the Question field. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 4.8 with vector… | |
| Analizada | Baja (2.3) | 0.24% | — | Concretecms Concrete CMS | 4/3/2026 | 17/6/2026 | Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configuration via group_id parameter which can leads to a security bypass since changes are saved prior to checking the CSRF token. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score… | |
| Analizada | Alta (8.9) | 0.95% | — | Concretecms Concrete CMS | 4/3/2026 | 17/6/2026 | Concrete CMS below version 9.4.8 is vulnerable to Remote Code Execution by stored PHP object injection into the Express Entry List block via the columns parameter. An authenticated administrator can store attacker-controlled serialized data in block configuration fields that are later passed to unserialize() without… | |
| Analizada | Media (4.8) | 0.28% | — | Concretecms Concrete CMS | 4/3/2026 | 17/6/2026 | In Concrete CMS below version 9.4.8, A stored cross-site scripting (XSS) vulnerability exists in the search block where page names and content are rendered without proper HTML encoding in search results. This allows authenticated, rogue administrators to inject malicious JavaScript through page names that executes… | |
| Analizada | Baja (2) | 0.44% | 💥 Exploit | Concretecms Concrete CMS | 5/8/2025 | 17/6/2026 | Concrete CMS versions 9 through 9.4.2 are vulnerable to Stored XSS from Home Folder on Members Dashboard page. Version 8 was not affected. A rogue admin could set up a malicious folder containing XSS to which users could be directed upon login. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score… | |
| Analizada | Media (4.8) | 0.33% | 💥 PoC | Concretecms Concrete CMS | 5/8/2025 | 17/6/2026 | Concrete CMS 9 to 9.4.2 and versions below 8.5.21 are vulnerable to Reflected Cross-Site Scripting (XSS) in the Conversation Messages Dashboard Page. Unsanitized input could cause theft of session cookies or tokens, defacement of web content, redirection to malicious sites, and (if victim is an admin), the execution… | |
| Analizada | Media (5.1) | 0.19% | — | Concretecms Concrete CMS | 3/4/2025 | 17/6/2026 | Concrete CMS version 9 below 9.4.0RC2 and versions below 8.5.20 are vulnerable to CSRF and XSS in the Concrete CMS Address attribute because addresses are not properly sanitized in the output when a country is not specified. Attackers are limited to individuals whom a site administrator has granted the ability to fill… | |
| Analizada | Media (4.8) | 0.33% | — | Concretecms Concrete CMS | 10/3/2025 | 17/6/2026 | Concrete CMS versions 9.0.0 through 9.3.9 are affected by a stored XSS in Folder Function.The "Add Folder" functionality lacks input sanitization, allowing a rogue admin to inject XSS payloads as folder names. The Concrete CMS security team gave this vulnerability a CVSS 4.0 Score of 4.8 with vector:… | |
| Modificada | Media (5.1) | 0.53% | — | Concretecms Concrete CMS | 25/9/2024 | 17/6/2026 | Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in Image Editor Background Color. A rogue admin could add malicious code to the Thumbnails/Add-Type. The Concrete CMS Security Team gave this a CVSS v4 score of 5.1 with vector… | |
| Modificada | Media (4.6) | 0.49% | — | Concretecms Concrete CMS | 25/9/2024 | 17/6/2026 | Concrete CMS versions 9 through 9.3.3 and versions below 8.5.19 are vulnerable to stored XSS in the calendar event addition feature because the calendar event name was not sanitized on output. Users or groups with permission to create event calendars can embed scripts, and users or groups with permission to modify… | |
| Analizada | Media (4.6) | 0.29% | — | Concretecms Concrete CMS | 17/9/2024 | 17/6/2026 | Concrete CMS versions 9.0.0 through 9.3.3 are affected by a stored XSS vulnerability in the "Top Navigator Bar" block. Since the "Top Navigator Bar" output was not sufficiently sanitized, a rogue administrator could add a malicious payload that could be executed when targeted users visited the home page.The Concrete… |