|
41
|
8.8 |
HIGH
Network
|
concretecms
|
concrete_cms
|
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id). The Concrete CMS security team gave this vulnerability a…
Update
|
CWE-352 CWE-1275
Origin Validation Error Sensitive Cookie with Improper SameSite Attribute
|
CVE-2026-8427
|
2026-05-27 03:49 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
42
|
8.8 |
HIGH
Network
|
concretecms
|
concrete_cms
|
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score o…
Update
|
CWE-352 CWE-1275
Origin Validation Error Sensitive Cookie with Improper SameSite Attribute
|
CVE-2026-8432
|
2026-05-27 03:46 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
43
|
7.2 |
HIGH
Network
|
concretecms
|
concrete_cms
|
Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the ExpressEntryList block controller. An rogue administrator with privileges to add …
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-8135
|
2026-05-27 03:44 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
44
|
6.5 |
MEDIUM
Network
|
concretecms
|
concrete_cms
|
Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/install/download/<remoteId>. The download() method in concrete/controllers/single_page/dash…
Update
|
CWE-352
Origin Validation Error
|
CVE-2026-8140
|
2026-05-27 03:43 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
45
|
4.8 |
MEDIUM
Network
|
concretecms
|
concrete_cms
|
Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration name. The OAuth authorize template renders the integration name (admin-controlled) through Concrete's t() translation he…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-8197
|
2026-05-27 03:34 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
46
|
5.4 |
MEDIUM
Network
|
concretecms
|
concrete_cms
|
Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validate or sanitize $height. Any user with editor privileges can inject malicious JavaScript that execute…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-8203
|
2026-05-27 03:33 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
47
|
8.8 |
HIGH
Network
|
concretecms
|
concrete_cms
|
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete. The The Concrete CMS security team gave this vulnerability a CVSS v.4.0 sco…
Update
|
CWE-352 CWE-1275
Origin Validation Error Sensitive Cookie with Improper SameSite Attribute
|
CVE-2026-8409
|
2026-05-27 03:32 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
48
|
8.8 |
HIGH
Network
|
concretecms
|
concrete_cms
|
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete. The The Concrete CMS security team gave this vulnerability a CVSS v.4.…
Update
|
CWE-352 CWE-1275
Origin Validation Error Sensitive Cookie with Improper SameSite Attribute
|
CVE-2026-8410
|
2026-05-27 03:31 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
49
|
7.5 |
HIGH
Network
|
nlnetlabs
|
unbound
|
NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL config…
Update
|
CWE-346
Origin Validation Error
|
CVE-2026-40622
|
2026-05-27 03:28 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
50
|
8.8 |
HIGH
Network
|
concretecms
|
concrete_cms
|
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 sco…
Update
|
CWE-352 CWE-1275
Origin Validation Error Sensitive Cookie with Improper SameSite Attribute
|
CVE-2026-8411
|
2026-05-27 03:26 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|