Concrete Cms
Vendor:
First CVE: Jul 28, 2014 · Active for 11 years
156
Total CVEs
More Total CVEs than 99% of tracked products
13.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Concrete Cms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 28, 2014
11 years ago
Most Recent CVE
Jun 10, 2026
48 days ago
CVE Severity & Scoring
Concrete Cms156 CVEs
70%
26%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (1.3%)
Network151 (96.8%)
Unknown3 (1.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low152 (97.4%)
High1 (0.6%)
Unknown3 (1.9%)
User Interaction
None53 (34.0%)
Unknown3 (1.9%)
Required100 (64.1%)
Privileges Required
Low32 (20.5%)
High47 (30.1%)
None74 (47.4%)
Unknown3 (1.9%)
Top CVEs
Signals from CVEs in this product scope (156 CVEs).
156 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-8434HIGH Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple(). The Concrete CMS security team gave this vulne | May 21, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-8433HIGH Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan(). The Concrete CMS security team gave this vulnerability | May 21, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-8432HIGH Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star(). The Concrete CMS security team gave this vulnerability a | May 21, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-8427HIGH Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id). The Concrete CMS security team gave t | May 21, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-8416HIGH Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id). The Concrete CMS security team gave this | May 21, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-8415HIGH Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder. The Concrete CMS security team gave this | May 21, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-8414HIGH Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate. The Concrete CMS security team gave this vulnerabilit | May 21, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-8413HIGH Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design. The Concrete CMS security team gave this vulnerabili | May 21, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-8412HIGH Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache. The Concrete CMS security team gave this vulnerabili | May 21, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-8411HIGH Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete. The Concrete CMS security team gave this vulnerabili | May 21, 2026 | 8.8 | 34 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (156 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
2.6% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (156 CVEs).
Media Mentions
Signals from CVEs in this product scope (156 CVEs).
Top CNAs Publishing CVEs For Concrete Cms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.4.7 | 1 | 6.5 | 0.3% | 0 | 0 |
| 9.4.0 | 1 | 6.5 | 0.2% | 0 | 0 |
| 9.2.1 | 7 | 5.2 | 0.6% | 0 | 0 |
| 9.0 | 1 | 7.5 | 1.4% | 0 | 0 |
| 8.4.3 | 1 | 4.8 | 1.0% | 0 | 0 |
| 8.2.0 | 1 | 7.2 | 1.0% | 0 | 0 |
| 8.1.0 | 2 | 6.3 | 2.0% | 0 | 1 |
| 5.7.3.1 | 2 | 7.5 | 0.8% | 0 | 0 |
| 5.7.2 | 1 | 4.3 | 1.9% | 0 | 0 |
| 5.6.2.1 | 2 | 4.7 | 2.6% | 0 | 0 |
| 5.6.2 | 2 | 4.7 | 2.6% | 0 | 0 |
| 5.6.1.2 | 2 | 4.7 | 2.6% | 0 | 0 |
| 5.6.1.1 | 2 | 4.7 | 2.6% | 0 | 0 |
| 5.6.1 | 2 | 4.7 | 2.6% | 0 | 0 |
| 5.4.2.2 | 2 | 4.7 | 2.6% | 0 | 0 |
| 5.4.2.1 | 2 | 4.7 | 2.6% | 0 | 0 |
| 5.4.2 | 2 | 4.7 | 2.6% | 0 | 0 |