Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-3153

18
FAUCET Score

CVE-2025-3153 is a Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) vulnerability affecting Concrete CMS versions below 9.4.0RC2 and 8.5.20, stemming from improper sanitization of address attributes when a country is not specified. This medium-severity vulnerability (CVSS 6.5) requires attacker interaction and limited privileges, potentially leading to limited information disclosure, data modification, and denial of service on the dashboard page. While a fix is available, it only applies to new data, necessitating a database search for pre-existing exploits. There is currently no evidence of active exploitation, public exploit code, or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5, < 8.5.20CPE match
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
< 8.5.20CPE matchmatch criteria
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
>= 9.0, < 9.4.0CPE matchmatch criteria
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
9.4.0CPE matchmatch criteria
cpe:2.3:a:concretecms:concrete_cms:9.4.0:rc1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.1MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
PASSIVE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
LOW
SS Confidentiality
LOW
SS Integrity
LOW
SS Availability
LOW
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 3rd percentile among its peer group of 15,239 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

composerpatch availablevia ghsa
Product: concrete5/concrete5Fixed in: 9.4.0RC2
composerpatch availablevia ghsa
Product: concrete5/concrete5Fixed in: 8.5.20
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-cmm4-p9v2-q453medium

Concrete CMS Vulnerable to Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)

Apr 3, 2025

References

documentation.concretecms.org / 9-x/developers/introduction/version-history/940-release-notes
Release Notes
github.com / concretecms/concretecms/pull/12511
Issue TrackingPatch
github.com / concretecms/concretecms/pull/12512
Issue TrackingPatch
github.com / concretecms/concretecms/releases/tag/8.5.20
Release Notes