CVE Vulnerability Database
Search and browse 397,909 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7890 | MEDIUM | 6.4 | 0.2% | May 21, 2026 | In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-s... |
| CVE-2026-7887 | MEDIUM | 6.4 | 0.2% | May 21, 2026 | For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status. A user with uIsActive=0 ... |
| CVE-2026-7886 | MEDIUM | 4.3 | 0.3% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter which can lea... |
| CVE-2026-7882 | MEDIUM | 4.3 | 0.1% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to unauthorized file deletion due to an Inverted CSRF token check in the Del... |
| CVE-2026-7881 | MEDIUM | 4.3 | 0.2% | May 21, 2026 | Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail block via... |
| CVE-2026-7879 | MEDIUM | 5.3 | 0.2% | May 21, 2026 | In Concrete CMS 9.5.0 and below, the submit_password() method in concrete/controllers/single_page/download_file.php all... |
| CVE-2026-6960 | CRITICAL | 9.8 | 0.7% | May 21, 2026 | The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in... |
| CVE-2026-5091 | MEDIUM | 5.1 | 0.2% | May 21, 2026 | Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions us... |
| CVE-2026-4929 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper output escaping of term... |
| CVE-2026-4093 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the widget/formatter rendering pipeline. Ve... |
| CVE-2026-22678 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the ... |
| CVE-2026-8428 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update')) but... |
| CVE-2026-8426 | HIGH | 8.8 | 0.2% | May 21, 2026 | Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/prepa... |
| CVE-2026-8421 | HIGH | 8.8 | 0.2% | May 21, 2026 | Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/singl... |
| CVE-2026-8417 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/do_up... |
| CVE-2026-8352 | — | — | — | May 21, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-8350 | HIGH | 8.8 | 0.3% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to pr... |
| CVE-2026-8205 | MEDIUM | 5.3 | 0.2% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calendar Block since action_get_events does no... |
| CVE-2026-8204 | MEDIUM | 5.3 | 0.2% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend Dialog which can allow... |
| CVE-2026-8203 | MEDIUM | 5.4 | 0.1% | May 21, 2026 | Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validate or sanitize $heigh... |
| CVE-2026-8197 | MEDIUM | 4.8 | 0.2% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration name. The OAuth authorize template render... |
| CVE-2026-8140 | MEDIUM | 6.5 | 0.1% | May 21, 2026 | Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/install/down... |
| CVE-2026-8135 | HIGH | 7.2 | 0.5% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the Ex... |
| CVE-2026-8134 | HIGH | 7.2 | 0.7% | May 21, 2026 | Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTempl... |
| CVE-2026-6826 | MEDIUM | 5.3 | 0.3% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to unauthenticated file usage disclosure via missing permission check in the... |
