Technology · Packagist
concrete5/concrete5 (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 46 vulnerabilities in concrete5/concrete5 (Packagist): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-10721, was published on 10 June 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
About concrete5/concrete5 (Packagist)
Concrete CMS (formerly concrete5) is an open-source content management system written in PHP.
Latest concrete5/concrete5 (Packagist) vulnerabilities
- CVE-2026-10721: Concrete CMS PHP object injection in Permission Cache and Search componentshighCVSS 8.4EPSS 0.1%
- CVE-2026-7888: Concrete CMS PHP object injection in Workflow and Form componentshighCVSS 8.4EPSS 0.2%
- CVE-2026-8353: Concrete CMS Stored XSS via page name in Atomik thememediumCVSS 4.8EPSS 0.1%
- CVE-2026-8347: Concrete CMS IDOR in Express association Reorder dialogmediumCVSS 4.3EPSS 0.2%
- CVE-2026-8340: Concrete CMS CSRF in Backend File Version ApprovalmediumCVSS 4.3EPSS 0.1%
- CVE-2026-8435: Concrete CMS CSRF in file version approvallowCVSS 2.3EPSS 0.1%
- CVE-2026-8434: Concrete CMS CSRF in file rescanMultiple controllerlowCVSS 2.3EPSS 0.1%
- CVE-2026-8433: Concrete CMS CSRF in file rescan controllerlowCVSS 2.3EPSS 0.1%
- CVE-2026-8432: Concrete CMS CSRF in file star controllerlowCVSS 2.3EPSS 0.1%
- CVE-2026-8427: Concrete CMS CSRF in removeFavoriteFolder backend controllerlowCVSS 2.3EPSS 0.1%
- CVE-2026-8416: Concrete CMS CSRF in addFavoriteFolder backend controllerlowCVSS 2.3EPSS 0.1%
- CVE-2026-8415: Concrete CMS CSRF in Express association reorderinglowCVSS 2.3EPSS 0.1%
- CVE-2026-8414: Concrete CMS CSRF in event duplication controllerlowCVSS 2.3EPSS 0.1%
- CVE-2026-8413: Concrete CMS CSRF in bulk page design controllerlowCVSS 2.3EPSS 0.1%
- CVE-2026-8412: Concrete CMS CSRF in bulk page cache controllerlowCVSS 2.3EPSS 0.1%
- CVE-2026-8411: Concrete CMS CSRF in bulk page deletion controllerlowCVSS 2.3EPSS 0.1%
- CVE-2026-8410: Concrete CMS CSRF in bulk log deletionlowCVSS 2.3EPSS 0.1%
- CVE-2026-8409: Concrete CMS CSRF in log deletion controllerlowCVSS 2.3EPSS 0.1%
- CVE-2026-8337: Concrete CMS IDOR in surveysmediumCVSS 6.3EPSS 0.2%
- CVE-2026-8327: Concrete CMS unverified password change and session bypassmediumCVSS 5.3EPSS 0.2%
- CVE-2026-8245: Concrete CMS Reflected XSS in Legacy PaginationmediumCVSS 6EPSS 0.1%
- CVE-2026-8240: Concrete CMS unauthenticated page metadata disclosure in summary templatesmediumCVSS 6.3EPSS 0.2%
- CVE-2026-8239: Concrete CMS IDOR in conversation rating endpointmediumCVSS 6.3EPSS 0.2%
- CVE-2026-8238: Concrete CMS IDOR in conversation message endpointmediumCVSS 6.3EPSS 0.2%
- CVE-2026-8237: Concrete CMS IDOR in conversation message detail endpointmediumCVSS 6.3EPSS 0.2%
Most severe concrete5/concrete5 (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-8135: Concrete CMS insecure deserialization in ExpressEntryList blockhighCVSS 8.9EPSS 0.5%
- CVE-2026-7888: Concrete CMS PHP object injection in Workflow and Form componentshighCVSS 8.4EPSS 0.2%
- CVE-2026-10721: Concrete CMS PHP object injection in Permission Cache and Search componentshighCVSS 8.4EPSS 0.1%
- CVE-2026-8350: Concrete CMS privilege escalation in bulk user assignmenthighCVSS 7.5EPSS 0.3%
- CVE-2026-8426: Concrete CMS CSRF to Remote Code Execution in package upgradeshighCVSS 7.5EPSS 0.2%
- CVE-2026-8421: Concrete CMS CSRF in install_package method leads to RCEhighCVSS 7.5EPSS 0.2%
- CVE-2026-8428: Concrete CMS CSRF in dashboard update controllerhighCVSS 7.5EPSS 0.1%
- CVE-2026-8417: Concrete CMS CSRF in package update dashboardhighCVSS 7.5EPSS 0.1%
- CVE-2026-8140: Concrete CMS CSRF in marketplace package downloaderhighCVSS 7.5EPSS 0.1%
- CVE-2026-8197: Concrete CMS Stored XSS in OAuth integration namehighCVSS 7.3EPSS 0.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/concrete5-concrete5.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "concrete5/concrete5 (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/concrete5-concrete5, 26 September 2026.