VDB
Sign up

package

Packagist/concrete5/concrete5

pkg:packagist/concrete5/concrete5

LOWPackagist
GHSA-44q4-354f-c826· CVE-2026-8435

Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion()

Modified: 9/10/2026

HIGHPackagist
GHSA-52pr-7vmf-2w7x· CVE-2026-7888

Concrete CMS is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components

Modified: 7/14/2026

HIGHPackagist
GHSA-5rj5-gfmr-hrc3· CVE-2026-8426

Concrete CMS does not validate a CSRF token before processing requests to `/dashboard/extend/update/prepare_remote_upgrade/<remoteMPID>`

Modified: 9/10/2026

LOWPackagist
GHSA-67hj-8239-cmf5· CVE-2026-8427

Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id)

Modified: 9/10/2026

LOWPackagist
GHSA-6fxm-r8p3-mx5c· CVE-2026-8433

Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan()

Modified: 9/10/2026

LOWPackagist
GHSA-6qjh-p324-694f· CVE-2026-8434

Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple()

Modified: 9/10/2026

LOWPackagist
GHSA-752x-23hp-jmv6· CVE-2026-8411

Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete

Modified: 9/10/2026

LOWPackagist
GHSA-98qf-jvwj-2r5f· CVE-2026-8414

Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate

Modified: 9/10/2026

LOWPackagist
GHSA-gjwq-9v8p-47w7· CVE-2026-7890

Concrete CMS's RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation

Modified: 9/10/2026

HIGHPackagist
GHSA-jr5g-qv3g-rxxx· CVE-2026-8417

Concrete does not validate a CSRF token before processing requests to `/dashboard/extend/update/do_update/<pkgHandle>`

Modified: 9/10/2026

LOWPackagist
GHSA-mpq2-mv8p-9wm6· CVE-2026-8413

Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design

Modified: 9/10/2026

LOWPackagist
GHSA-qj94-6rx6-27fr· CVE-2026-8416

Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id)

Modified: 9/10/2026