Security

Last week, the Symfony team disclosed a substantial set of security fixes across Symfony and Twig after an audit performed with Anthropic’s Claude Mythos project. Symfony reports that the audit uncovered 19 legitimate vulnerabilities across Symfony and Twig components, all of which were patched in their latest releases.


Version 9.5.1 of Concrete CMS delivers a substantial security hardening update for the platform, resolving 35 vulnerabilities across core CMS functionality, package management, authentication flows, file handling, administrative workflows, and authorization controls.


Maintaining the security and integrity of your digital presence is an important priority. We have just released a series of security updates with Concrete CMS version 9.4.8 to address several vulnerabilities ranging from Cross-Site Scripting (XSS) to Remote Code Execution (RCE). 

Important Note: All fixes listed below are applicable only to Concrete CMS version 9. There will be no further security fixes backported to version 8. We strongly recommend all users still on version 8 to plan their migration to v9 to remain protected.


CVE-2025-8571 – Reflected XSS in Conversation Messages Dashboard Page


Concrete CMS 9.4.0 Release Candidates 1 (RC1) & 2 (RC2) which was released in March 2025 fixed Stored Cross-Site Scripting (XSS) in Folder Function CVE-2025-0660 Versions below 8 were not affected: 


You might notice that a number of Concrete CMS CVEs have higher CVSS 4.0 risk rankings assigned by the CNA (that’s us!) than the last time you looked at them. You aren’t hallucinating, we’ve made some adjustments, and some Concrete CVEs are now ranked as “medium” instead of “low” vulnerabilities. Guanqun Yang noticed that the Concrete team was inconsistent with our Attack Complexity (AC) CVSS 4.0 risk scoring; thanks for bringing it to our attention. 


The following CVEs affecting both version 9 below 9.3.4 and all other concrete versions below 8.5.19 have been sent to MITRE to publish:


Thanks so much to all the community members who report vulnerabilities following the process outlined on https://www.concretecms.org/security and https://hackerone.com/concretecms?type=team so that they can be triaged and remediated by the Concrete Team!


We will be publishing a number of CVEs today which were remediated with Concrete CMS versions 8.5.16 and 9.2.8. 


The Concrete CMS Team is publishing CVE-2024-2179 with the release of 9.2.7; Concrete CMS version 9 before 9.2.7 is vulnerable to Stored XSS via the Name field of a Group type since there is insufficient validation of administrator provided data for that field.