Exposição de Concrete CMS

CMS
106
score de exposição
4.122
sites usam
0
em exploração
1
críticos
Análise Vexday

Com 74 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o Concrete CMS apresenta taxa de exploração abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. O dado mais relevante para atenção é o volume recente: 46 vulnerabilidades surgiram nos últimos 90 dias, sugerindo um ciclo ativo de descoberta e divulgação que demanda acompanhamento contínuo. O tipo de falha mais comum é CWE-352 (Cross-Site Request Forgery), padrão que aponta para fragilidades recorrentes na validação de requisições e que historicamente exige correções consistentes em múltiplos pontos da aplicação. A CVE mais perigosa atualmente, CVE-2024-1247, possui EPSS de 0,0124, refletindo probabilidade ainda baixa de exploração em larga escala, mas sua presença junto à única vulnerabilidade crítica do conjunto recomenda priorização nas equipes de patch management.

CVEs

74 resultados
CVE-2025-0660MEDIUMStored XSS in Folder Function by Rogue AdminEPSS 0.3%CVE-2024-2179LOWConcrete CMS version 9 before 9.2.7 is vulnerable to Stored XSS via the Name field of a Group typeEPSS 0.3%CVE-2024-4353MEDIUMStored XSS in Generate Board Name Input FieldEPSS 0.3%CVE-2026-8350HIGHConcrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to privilege escalation to Administrative GroupEPSS 0.3%CVE-2026-7886LOWConcrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameterEPSS 0.3%CVE-2024-8660MEDIUMStored XSS in the "Top Navigator Bar" blockEPSS 0.3%CVE-2026-6826MEDIUMConcrete 9.5.0 and below has file usage disclosure via missing permission check in Usage controllerEPSS 0.3%CVE-2026-7879MEDIUMConcrete CMS 9.5.0 and below is vulnerable to File Download Authorization Bypass in submit_password()EPSS 0.2%CVE-2026-3240MEDIUMConcrete CMS below 9.4.8 is vulnerable to Stored XSS via Legacy formEPSS 0.2%CVE-2026-8205MEDIUMConcrete CMS 9.5.0 and below is vulnerable to authorization bypass in Calendar Block since action_get_events does not check canView on the calendarEPSS 0.2%CVE-2026-8204MEDIUMConcrete CMS 9.5.0 and below is vulnerable to Authorization Bypass in the Calendar Event Frontend DialogEPSS 0.2%CVE-2026-3241MEDIUMConcrete CMS below version 9.4.8 is vulnerable to a stored cross-site scripting (XSS) in the "Legacy Form" block.EPSS 0.2%CVE-2026-2994LOWConcrete CMS below 9.4.8 is vulnerable to CSRF by a Rogue Admin using the Anti-Spam Allowlist GroupEPSS 0.2%CVE-2026-7881MEDIUMConcrete CMS 9.5.0 and below is vulnerable to IDOR in the Express Entry Detail blockEPSS 0.2%CVE-2026-8236MEDIUMConcrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate for endpoint /ccm/system/dialogs/file/usage/{fID}EPSS 0.2%CVE-2026-8237MEDIUMConcrete CMS 9.5.0 and below is vulnerable to IDOR in the`/ccm/frontend/conversations/message_detail` endpointEPSS 0.2%CVE-2026-8238MEDIUMConcrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/message_page' allowing unauthenticated read of any conversation messageEPSS 0.2%CVE-2026-3242MEDIUMConcrete CMS below 9.4.8 is vulnerable to Stored XSS in the Switch Language blockEPSS 0.2%CVE-2026-8239MEDIUMConcrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/get_rating'EPSS 0.2%CVE-2026-8240MEDIUMConcrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure in Backend\SummaryTemplateEPSS 0.2%