Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Concrete CMS versions before 9.5.3 contain an authorization bypass vulnerability in the Express entry submission process. The system incorrectly checks permissions against the entity of the posted form rather than the entity identified by the dashboard route, allowing users with permission to add entries to one Express object to create entries in another unauthorized Express object. This flaw can lead to unauthorized data pollution, triggering of workflows, or injection of content into administrative processes. The vulnerability has a CVSS v4.0 score of 5.1, indicating medium severity. Join the discussion | GCVE Database | 09/11/2026, 21:31:25 UTC Added: 09/12/2026, 00:43:18 UTC |
0 Concrete CMS versions 9.0.0 through 9.5.2 contain a stored cross-site scripting (XSS) vulnerability in the Board Custom Slot dialog. This occurs because the save_template endpoint accepts and stores client-supplied data without properly verifying or encoding it, allowing a user with board content editing permissions to inject JavaScript payloads. These payloads execute in the browsers of users who view the affected board slot, including anonymous visitors and dashboard users, potentially leading to session or action takeover and privilege escalation. Versions prior to 9.0.0 are not affected as they lack the Boards feature. Join the discussion | GCVE Database | 09/11/2026, 21:31:25 UTC Added: 09/12/2026, 00:43:18 UTC |
0 Concrete CMS versions before 9.5.3 have a Cross-Site Request Forgery (CSRF) vulnerability in the Move Multiple Groups feature. The affected endpoint does not validate an action token, allowing an authenticated user to be tricked into moving group nodes without their intent. This can alter group membership inheritance and change effective permissions. The vulnerability has a CVSS v4.0 base score of 5.7, indicating medium severity. Join the discussion | GCVE Database | 09/11/2026, 21:31:25 UTC Added: 09/12/2026, 00:43:18 UTC |
0 Concrete CMS versions below 9.5.3 have a vulnerability where object-level authorization checks are not performed when updating a Page Type. This allows a signed-in dashboard user with permission to edit one Page Type to modify other Page Types outside their authorization scope. The vulnerability arises because the update_page_type token is action- and user-scoped but not object-scoped, failing to restrict which Page Type can be targeted. Join the discussion | GCVE Database | 09/11/2026, 21:31:25 UTC Added: 09/12/2026, 00:43:18 UTC |
0 Concrete CMS versions 9.5.0 through 9.5.2 contain an open redirect vulnerability via the rcURL parameter. This flaw allows attackers to craft links on the legitimate site that redirect users to arbitrary external sites immediately after authentication or during registration, potentially facilitating phishing attacks and credential theft. Versions prior to 9.5.0 are not affected as they do not include the vulnerable parameter or allowlist. Join the discussion | GCVE Database | 09/11/2026, 21:31:25 UTC Added: 09/12/2026, 00:43:16 UTC |
Concrete CMS versions 9 through 9.5.2 have a Server-Side Template Injection (SSTI) vulnerability in the Theme Customizer. This occurs because style values submitted via the customizer are interpolated into server-compiled LESS source without proper neutralization, allowing injection of arbitrary LESS directives. An attacker with Theme Customization permission can exploit this to read arbitrary server files and access internal network resources. The compiled CSS cache publicly exposes sensitive data such as database credentials and private keys. The vulnerability has a CVSS v4.0 score of 5.9, indicating medium severity. Join the discussion | GCVE Database | 09/11/2026, 21:31:18 UTC Added: 09/12/2026, 00:43:34 UTC |
0 Concrete CMS versions before 9.5.3 contain a vulnerability in the Calendar event duplicate dialog controller where an anti-CSRF token was not validated. This flaw allows an authenticated user with add-event permission to create duplicate calendar events via a crafted cross-site request. The vulnerability was assigned a CVSS v4.0 score of 5.3, indicating a medium severity level. Join the discussion | GCVE Database | 09/11/2026, 21:31:18 UTC Added: 09/12/2026, 00:43:34 UTC |
0 Concrete CMS 9.2.0 to 9.5.2 contain a missing authorization vulnerability in the REST API Groups list endpoint. The listGroups() method in concrete/src/Api/Controller/Groups.php registers a permissions checker callback that unconditionally returns true, so no per-object (tree node) authorization is enforced when the group collection is returned. An authenticated user whose API token carries the groups:read scope can call GET /ccm/api/1.0/groups and receive every group on the site regardless of the view permissions on those groups, disclosing the organization's group structure, roles, and access hierarchy. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.0 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting. Join the discussion | GCVE Database | 09/11/2026, 18:31:26 UTC Added: 09/11/2026, 22:20:42 UTC |
Concrete CMS versions below 9.5.3 have a vulnerability where view assets for every sub-block of a Stack, Container, or layout area are registered without verifying if the requesting user has permission to view that sub-block. This allows an unauthenticated visitor to access configuration values, such as a Google Maps API key, from any public page embedding the affected components, bypassing block-level permission restrictions. The vulnerability affects any sub-block type that outputs configuration values via asset or header hooks. Join the discussion | GCVE Database | 09/09/2026, 00:30:29 UTC Added: 09/09/2026, 00:52:50 UTC |
0 ConcreteCMS version 9.4.7 contains a Denial of Service (DoS) vulnerability in its File Manager component. The vulnerability arises from the 'download' method in 'concrete/controllers/backend/file.php', which improperly handles memory when creating zip archives by loading entire file contents into PHP memory. An authenticated attacker can exploit this by requesting bulk downloads of large files, causing an Out-Of-Memory (OOM) condition that crashes the PHP-FPM process and results in HTTP 500 errors. This vulnerability does not affect confidentiality or integrity but severely impacts availability. Exploitation requires authentication but no user interaction beyond sending the request. There are no known exploits in the wild currently, and no patches have been linked yet. The CVSS score is 6. Join the discussion | CVE Database V5 | 03/24/2026, 00:00:00 UTC Added: 03/24/2026, 14:45:55 UTC |
Showing 1 to 10 of 10 results