Concrete CMS

First CVE: Feb 9, 2024Active for: 2 years
73
CVEs Published
More CVEs Published than 66% of tracked CNAs
24.3
Avg CVEs / Year
More Avg CVEs / Year than 73% of tracked CNAs
6.1
Avg CVSS Score
Higher Avg CVSS Score than 12% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Concrete CMS as a CNA, 100.0% affect products that Concrete CMS develops as a vendor.

100.0%
Self-reported: 73Third-party: 0

Of all the CVEs published that affect products developed by Concrete CMS, 46.8% are self-published by Concrete CMS as a CNA.

46.8%
53.2%
Self-published: 73Published by other CNAs: 83

Trends Over Time

The number and severity of CVEs published by Concrete CMS over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 9, 2024
2 years ago
Most Recent CVE
Jun 10, 2026
44 days ago

Top CVEs

All CVEs published by Concrete CMS as a CNA, regardless of affected vendor or product.

73 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple(). The Concrete CMS security team gave this vulne
May 21, 20268.835NONO
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan(). The Concrete CMS security team gave this vulnerability
May 21, 20268.835NONO
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star(). The Concrete CMS security team gave this vulnerability a
May 21, 20268.835NONO
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id). The Concrete CMS security team gave t
May 21, 20268.835NONO
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id). The Concrete CMS security team gave this
May 21, 20268.835NONO
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder. The Concrete CMS security team gave this
May 21, 20268.835NONO
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate. The Concrete CMS security team gave this vulnerabilit
May 21, 20268.834NONO
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design. The Concrete CMS security team gave this vulnerabili
May 21, 20268.834NONO
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache. The Concrete CMS security team gave this vulnerabili
May 21, 20268.834NONO
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete. The Concrete CMS security team gave this vulnerabili
May 21, 20268.834NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA73 CVEs
Severity distribution among all CVEs352,294 CVEs
MediumHigh
Attack Vector
Local2 (2.7%)
Network71 (97.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low73 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None21 (28.8%)
Unknown0 (0.0%)
Required52 (71.2%)
Privileges Required
Low12 (16.4%)
High31 (42.5%)
None30 (41.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (73 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.4% of CVEs· 84th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Concrete CMS as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Concrete CMS as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs