Concrete CMS is an open-source content management system that has accumulated vulnerabilities across a modest but focused product portfolio, making it a well-represented player in the web application security landscape despite its narrow scope. The vendor's exposure centers on a characteristic web-application weakness profile: cross-site scripting, cross-site request forgery, improper input validation, and authorization bypass issues that arise from the challenges of sanitizing user content and managing session state in a self-hosted CMS. These classes reflect the vendor's role as a customizable platform where site builders integrate user-generated content and plugins, expanding the attack surface for injection and context-confusion flaws. Defenders deploying Concrete CMS should prioritize input validation hardening, session-cookie configuration review, and timely patching; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Concrete CMS over time
Of all the CVEs published by Concrete CMS as a CNA, 100.0% affect products that Concrete CMS develops as a vendor.
Of all the CVEs published that affect products developed by Concrete CMS, 46.8% are self-published by Concrete CMS as a CNA.
Signals from CVEs in this vendor scope (156 CVEs).
156 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-8434HIGH Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple(). The Concrete CMS security team gave this vulne | May 21, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-8433HIGH Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan(). The Concrete CMS security team gave this vulnerability | May 21, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-8432HIGH Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star(). The Concrete CMS security team gave this vulnerability a | May 21, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-8427HIGH Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id). The Concrete CMS security team gave t | May 21, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-8416HIGH Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id). The Concrete CMS security team gave this | May 21, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-8415HIGH Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder. The Concrete CMS security team gave this | May 21, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-8414HIGH Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate. The Concrete CMS security team gave this vulnerabilit | May 21, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-8413HIGH Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design. The Concrete CMS security team gave this vulnerabili | May 21, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-8412HIGH Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache. The Concrete CMS security team gave this vulnerabili | May 21, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-8411HIGH Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete. The Concrete CMS security team gave this vulnerabili | May 21, 2026 | 8.8 | 34 | NO | NO |
Signals from CVEs in this vendor scope (156 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Concrete CMS.
Media articles that mention a CVE ID that affects a product developed by Concrete CMS — matched by CVE ID, not by vendor name.