Technology · Concrete CMS
Concrete CMS vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 108 vulnerabilities in Concrete CMS: 0 in the last 7 days and 62 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-85387, was published on 16 September 2026.
- Last 7 days
- 0
- Last 90 days
- 62
- Critical, all time
- 2
- Exploited in the wild
- 0
About Concrete CMS
Concrete CMS is an open-source content management system designed for ease of use by both developers and content editors.
Latest Concrete CMS vulnerabilities
- CVE-2026-85387: Concrete CMS OAuth REST API authorization bypasshighCVSS 7.1EPSS 0.3%
- CVE-2026-18120: Concrete CMS unauthenticated Express entry search disclosuremediumCVSS 5.9EPSS 0.3%
- CVE-2026-87031: Concrete CMS REST API user creation permission bypasslowCVSS 2.7EPSS 0.3%
- CVE-2026-87028: Concrete CMS access control bypass in board custom-slot previewmediumCVSS 6.5EPSS 0.4%
- CVE-2026-85386: Concrete CMS stored XSS via XML file upload in Form BlockmediumCVSS 6.1EPSS 0.2%
- CVE-2026-85385: Concrete CMS stored XSS in user timezone fieldcriticalCVSS 9.6EPSS 0.5%
- CVE-2026-81927: Concrete CMS stored XSS in SVG file handlingmediumCVSS 5.4EPSS 0.2%
- CVE-2026-81926: Concrete CMS stored XSS in page path duplicate dialogmediumCVSS 6.1EPSS 0.3%
- CVE-2026-18426: Concrete CMS Express Form block authorization bypassmediumCVSS 6.5EPSS 0.2%
- CVE-2026-81925: Concrete CMS reflected XSS in conversation date formatmediumCVSS 6.1EPSS 0.3%
- CVE-2026-18425: Concrete CMS dashboard sitemap reorder authorization bypasslowCVSS 2.7EPSS 0.1%
- CVE-2026-18424: Concrete CMS Server-Side Request Forgery in remote file importhighCVSS 7.1EPSS 0.2%
- CVE-2026-18423: Concrete CMS insecure direct object reference in Express saved search presetshighCVSS 7.1EPSS 0.3%
- CVE-2026-18422: Concrete CMS authorization and CSRF bypass in multilingual page assignmentmediumCVSS 6.5EPSS 0.4%
- CVE-2026-81924: Concrete CMS CSRF in theme page-template activationmediumCVSS 6.5EPSS 0.2%
- CVE-2026-81923: Concrete CMS SEO Bulk Update privilege escalationlowCVSS 2.7EPSS 0.3%
- CVE-2026-81922: Concrete CMS authorization bypass in sitemap page reorderinglowCVSS 2.7EPSS 0.3%
- CVE-2026-81921: Concrete CMS OAuth 2.0 refresh token account status bypassmediumCVSS 5.4EPSS 0.2%
- CVE-2026-81920: Concrete CMS CSRF in dashboard SEO Excluded Words pagemediumCVSS 4.3EPSS 0.2%
- CVE-2026-81919: Concrete CMS CSRF in block arrangement endpointmediumCVSS 4.3EPSS 0.1%
- CVE-2026-68534: Concrete CMS stored cross-site scripting in Express entry labelsinfoCVSS 2.3EPSS 0.6%
- CVE-2026-68533: Concrete CMS authorization bypass in file upload endpointinfoCVSS 2.3EPSS 0.4%
- CVE-2026-68532: Concrete CMS dashboard group type CSRF in delete actioninfoCVSS 2.3EPSS 0.3%
- CVE-2026-68531: Concrete CMS SQL wildcard injection in search filtersinfoCVSS 2.1EPSS 0.5%
- CVE-2026-68530: Concrete CMS authorization bypass in board instance actionsinfoCVSS 2.1EPSS 0.5%
Most severe Concrete CMS vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-85385: Concrete CMS stored XSS in user timezone fieldcriticalCVSS 9.6EPSS 0.5%
- CVE-2026-18119: Concrete CMS stored cross-site scripting in Block Design dialogcriticalCVSS 9EPSS 0.3%
- CVE-2026-8135: Concrete CMS insecure deserialization in ExpressEntryList blockhighCVSS 8.9EPSS 0.5%
- CVE-2026-81901: Concrete CMS REST API authorization bypass in page update endpointhighCVSS 8.7EPSS 0.4%
- CVE-2026-7888: Concrete CMS PHP object injection in Workflow and Form componentshighCVSS 8.4EPSS 0.2%
- CVE-2026-10721: Concrete CMS PHP object injection in Permission Cache and Search componentshighCVSS 8.4EPSS 0.1%
- CVE-2026-81902: Concrete CMS CSRF token validation bypass in block removalhighCVSS 8.1EPSS 0.2%
- CVE-2026-8350: Concrete CMS privilege escalation in bulk user assignmenthighCVSS 7.5EPSS 0.3%
- CVE-2026-18110: Concrete CMS user selector autocomplete authorization bypasshighCVSS 7.5EPSS 0.3%
- CVE-2026-8426: Concrete CMS CSRF to Remote Code Execution in package upgradeshighCVSS 7.5EPSS 0.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 18 | 0 | |
| 14 Sep 2026 | 44 | 2 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/concrete-cms.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Concrete CMS vulnerabilities", https://junglewise.ai/threats/technologies/concrete-cms, 26 September 2026.