<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Concretecms on CVE Alert &amp; Security Feed</title><link>https://cvealert.net/vendors/concretecms/</link><description>Recent content in Concretecms on CVE Alert &amp; Security Feed</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 22 May 2026 15:16:26 +0000</lastBuildDate><atom:link href="https://cvealert.net/vendors/concretecms/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-8340</title><link>https://cvealert.net/posts/cve-2026-8340/</link><pubDate>Fri, 22 May 2026 15:16:26 +0000</pubDate><guid>https://cvealert.net/posts/cve-2026-8340/</guid><description>Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edit_file_contents permission is CSRF&amp;rsquo;d into publishing an attacker-chosen previously-uploaded version (downgrade to an older version of a file, or activation of a co-editor&amp;rsquo;s unpublished version). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.</description></item><item><title>CVE-2026-8347</title><link>https://cvealert.net/posts/cve-2026-8347/</link><pubDate>Fri, 22 May 2026 15:16:26 +0000</pubDate><guid>https://cvealert.net/posts/cve-2026-8347/</guid><description>Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog.  This can cause Cross-entity state tampering with view-only permission on one entry. To be affected, a website has to be using express and relying on express entity ordering. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.</description></item><item><title>CVE-2026-8353</title><link>https://cvealert.net/posts/cve-2026-8353/</link><pubDate>Fri, 22 May 2026 15:16:26 +0000</pubDate><guid>https://cvealert.net/posts/cve-2026-8353/</guid><description>Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inject arbitrary JavaScript that executes in the context of any authenticated user visiting the affected account pages. This can lead to session hijacking, credential theft, malicious actions performed on behalf of users, and potential privilege escalation. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</description></item></channel></rss>