<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:slash="http://purl.org/rss/1.0/modules/slash/">
  <channel>
    <title>Concrete CMS Security Announcements</title>
    <description>Security related issues for Concrete CMS</description>
    <generator>Laminas_Feed_Writer 2 (https://getlaminas.org)</generator>
    <link>https://www.concretecms.org/about/project-news/security</link>
    <item>
      <title>Security Update: Fixes for Concrete CMS v9</title>
      <description><![CDATA[<p><img src="https://www.concretecms.com/application/files/1416/5350/7967/Security_Announcement.png" /></p>Concrete CMS 9.4.8 includes security updates addressing vulnerabilities including Remote Code Execution (RCE), Cross-Site Scripting (XSS), and CSRF. Users on version 8 are encouraged to plan migration to version 9.]]></description>
      <pubDate>Wed, 04 Mar 2026 17:20:00 +0000</pubDate>
      <link>https://www.concretecms.org/about/project-news/security/security-update-fixes-for-concrete-cms-v9</link>
      <guid>https://www.concretecms.org/about/project-news/security/security-update-fixes-for-concrete-cms-v9</guid>
      <slash:comments>0</slash:comments>
    </item>
    <item>
      <title>Security Fixes in Concrete 8.5.21 and CMS 9.4.3</title>
      <description><![CDATA[<p><img src="https://www.concretecms.com/application/files/1416/5350/7967/Security_Announcement.png" /></p>Security Fixes Included in Concrete 8.5.21 and/or CMS 9.4.3]]></description>
      <pubDate>Wed, 06 Aug 2025 18:55:00 +0000</pubDate>
      <link>https://www.concretecms.org/about/project-news/security/security-fixes-in-concrete-8521-and-cms-943</link>
      <guid>https://www.concretecms.org/about/project-news/security/security-fixes-in-concrete-8521-and-cms-943</guid>
      <slash:comments>0</slash:comments>
    </item>
    <item>
      <title>2025-04-03 Concrete CMS Security Advisory - Security fixes in 9.4.0 Release Candidates</title>
      <description><![CDATA[<p><img src="https://www.concretecms.com/application/files/6417/2134/1143/Colorful_Security_Locks.jpg" /></p>Concrete CMS 9.4.0 Release Candidate 1 (RC1) which was released in March 2025 fixed Stored Cross-Site Scripting (XSS)]]></description>
      <pubDate>Fri, 04 Apr 2025 13:18:00 +0000</pubDate>
      <link>https://www.concretecms.org/about/project-news/security/2025-04-03-concrete-cms-security-advisory-security-fixes-in-940-release-candidates</link>
      <guid>https://www.concretecms.org/about/project-news/security/2025-04-03-concrete-cms-security-advisory-security-fixes-in-940-release-candidates</guid>
      <slash:comments>0</slash:comments>
    </item>
    <item>
      <title>2025-01-20 Concrete Security Advisory - CVEs upgraded to “Medium” </title>
      <description><![CDATA[<p><img src="https://www.concretecms.com/application/files/1416/5350/7967/Security_Announcement.png" /></p>You might notice that a number of Concrete CMS CVEs have higher CVSS 4.0 risk rankings assigned by the CNA (that’s us!) than the last time you looked at them. ]]></description>
      <pubDate>Tue, 21 Jan 2025 20:55:00 +0000</pubDate>
      <link>https://www.concretecms.org/about/project-news/security/2025-01-20-concrete-security-advisory-cves-upgraded-to-medium</link>
      <guid>https://www.concretecms.org/about/project-news/security/2025-01-20-concrete-security-advisory-cves-upgraded-to-medium</guid>
      <slash:comments>0</slash:comments>
    </item>
    <item>
      <title>New Concrete CMS CVEs Published in conjunction with releases 9.3.4 and 8.5.19</title>
      <description><![CDATA[<p><img src="https://www.concretecms.com/application/files/6517/2556/0081/Privacy_2.jpg" /></p>The following CVEs affecting both version 9 below 9.3.4 and all other concrete versions below 8.5.19 have been sent to MITRE to publish]]></description>
      <pubDate>Fri, 13 Sep 2024 13:10:00 +0000</pubDate>
      <link>https://www.concretecms.org/about/project-news/security/new-concrete-cms-cves-published-in-conjunction-with-releases-934-and-8519</link>
      <guid>https://www.concretecms.org/about/project-news/security/new-concrete-cms-cves-published-in-conjunction-with-releases-934-and-8519</guid>
      <slash:comments>0</slash:comments>
    </item>
    <item>
      <title>Concrete CMS Security Fixes with 9.3.3 and 8.5.18</title>
      <description><![CDATA[<p><img src="https://www.concretecms.com/application/files/1117/0802/1430/Security_photos.jpg" /></p>]]></description>
      <pubDate>Thu, 08 Aug 2024 15:04:00 +0000</pubDate>
      <link>https://www.concretecms.org/about/project-news/security/concrete-cms-security-fixes-with-933-and-8518</link>
      <guid>https://www.concretecms.org/about/project-news/security/concrete-cms-security-fixes-with-933-and-8518</guid>
      <slash:comments>0</slash:comments>
    </item>
    <item>
      <title>2024-04-03 Concrete CMS New Cross Site Scripting CVEs</title>
      <description><![CDATA[<p><img src="https://www.concretecms.com/application/files/1416/5350/7967/Security_Announcement.png" /></p>We will be publishing a number of CVEs today which were remediated with Concrete CMS versions 8.5.16 and 9.2.8. ]]></description>
      <pubDate>Wed, 03 Apr 2024 19:20:00 +0000</pubDate>
      <link>https://www.concretecms.org/about/project-news/security/2024-04-03-concrete-cms-new-cross-site-scripting-cves</link>
      <guid>https://www.concretecms.org/about/project-news/security/2024-04-03-concrete-cms-new-cross-site-scripting-cves</guid>
      <slash:comments>0</slash:comments>
    </item>
    <item>
      <title>2024-03-04 Concrete Security Advisory</title>
      <description><![CDATA[<p><img src="https://www.concretecms.com/application/files/1416/5350/7967/Security_Announcement.png" /></p>The Concrete CMS Team is publishing CVE-2024-2179 with the release of 9.2.7; Concrete CMS version 9 before 9.2.7 is vulnerable to Stored XSS via the Name field of a Group type since there is insufficient validation of administrator provided data for that field.]]></description>
      <pubDate>Wed, 06 Mar 2024 14:04:00 +0000</pubDate>
      <link>https://www.concretecms.org/about/project-news/security/2024-03-04-concrete-security-advisory</link>
      <guid>https://www.concretecms.org/about/project-news/security/2024-03-04-concrete-security-advisory</guid>
      <slash:comments>0</slash:comments>
    </item>
    <item>
      <title>CKEditor 4.22.1 and Concrete CMS Security Updates</title>
      <description><![CDATA[<p><img src="https://www.concretecms.com/application/files/1416/5350/7967/Security_Announcement.png" /></p>On February 7th, 2024, we received a bug report that the rich text editor in Concrete CMS 8 and 9 was displaying a strange and alarming warning. Learn more about this warning, what it's regarding, how to suppress it and what we're doing about it going forward.
]]></description>
      <pubDate>Mon, 12 Feb 2024 14:26:00 +0000</pubDate>
      <link>https://www.concretecms.org/about/project-news/security/ckeditor-4221-and-concrete-cms-security-updates</link>
      <guid>https://www.concretecms.org/about/project-news/security/ckeditor-4221-and-concrete-cms-security-updates</guid>
      <slash:comments>0</slash:comments>
    </item>
    <item>
      <title>3 New Very Low Concrete CMS CVEs 2024-02-04 Security Advisory</title>
      <description><![CDATA[<p><img src="https://www.concretecms.com/application/files/1416/5350/7967/Security_Announcement.png" /></p>We will be  publishing three CVEs for very low vulnerabilities that were reported and fixed in Concrete version 9.2.5. These vulnerabilities affected Concrete version 9 only. 
]]></description>
      <pubDate>Wed, 07 Feb 2024 14:26:00 +0000</pubDate>
      <link>https://www.concretecms.org/about/project-news/security/2024-02-04-security-advisory</link>
      <guid>https://www.concretecms.org/about/project-news/security/2024-02-04-security-advisory</guid>
      <slash:comments>0</slash:comments>
    </item>
    <item>
      <title>Concrete CMS will Manage Concrete CVEs starting now!</title>
      <description><![CDATA[<p><img src="https://www.concretecms.com/application/files/1416/5350/7967/Security_Announcement.png" /></p>Concrete CMS has just been authorized by the CVE Program as a CVE Numbering Authority (CNA). Concrete CMS will be managing Concrete CMS CVEs created as of today going forward for supported versions of Concrete CMS.]]></description>
      <pubDate>Fri, 05 Jan 2024 14:41:00 +0000</pubDate>
      <link>https://www.concretecms.org/about/project-news/security/concrete-cms-will-manage-concrete-cves-starting-now</link>
      <guid>https://www.concretecms.org/about/project-news/security/concrete-cms-will-manage-concrete-cves-starting-now</guid>
      <slash:comments>0</slash:comments>
    </item>
    <item>
      <title>A Comprehensive Overview of CVEs in Supported Versions of Concrete CMS</title>
      <description><![CDATA[<p><img src="https://www.concretecms.com/application/files/1416/5350/7967/Security_Announcement.png" /></p>We are pleased to announce that we are sharing our tracker for the Disclosed Common Vulnerabilities and Exposures (CVEs) affecting supported versions of Concrete CMS. ]]></description>
      <pubDate>Fri, 15 Dec 2023 20:41:00 +0000</pubDate>
      <link>https://www.concretecms.org/about/project-news/security/cves-in-supported-versions-of-concrete-cms</link>
      <guid>https://www.concretecms.org/about/project-news/security/cves-in-supported-versions-of-concrete-cms</guid>
      <slash:comments>0</slash:comments>
    </item>
    <item>
      <title>2023-12-05 Concrete CMS New CVEs and CVE Updates</title>
      <description><![CDATA[<p><img src="https://www.concretecms.com/application/files/1416/5350/7967/Security_Announcement.png" /></p>We are excited to announce the release of Concrete version 9.2.3, as well as an update for Concrete CMS version 8.5, now at version 8.5.14. These releases come with a number of security updates, reinforcing our commitment to the security and reliability of Concrete CMS. ]]></description>
      <pubDate>Wed, 06 Dec 2023 14:35:00 +0000</pubDate>
      <link>https://www.concretecms.org/about/project-news/security/2023-12-05-concrete-cms-new-cves-and-cve-updates</link>
      <guid>https://www.concretecms.org/about/project-news/security/2023-12-05-concrete-cms-new-cves-and-cve-updates</guid>
      <slash:comments>0</slash:comments>
    </item>
    <item>
      <title>Mitigate League OAuth2 Server Vulnerability</title>
      <description><![CDATA[<p><img src="https://www.concretecms.com/application/files/1416/5350/7967/Security_Announcement.png" /></p>]]></description>
      <pubDate>Thu, 23 Nov 2023 20:05:00 +0000</pubDate>
      <link>https://www.concretecms.org/about/project-news/security/mitigate-league-oauth2-server-vulnerability</link>
      <guid>https://www.concretecms.org/about/project-news/security/mitigate-league-oauth2-server-vulnerability</guid>
      <slash:comments>0</slash:comments>
    </item>
    <item>
      <title>2023-11-09 Security Blog about updated CVEs and new releases</title>
      <description><![CDATA[<p><img src="https://www.concretecms.com/application/files/1416/5350/7967/Security_Announcement.png" /></p>There have been a number of medium and low security vulnerabilities that have been fixed in version 9.2.2. ]]></description>
      <pubDate>Thu, 09 Nov 2023 01:53:00 +0000</pubDate>
      <link>https://www.concretecms.org/about/project-news/security/2023-11-09-security-blog-about-updated-cves-and-new-release</link>
      <guid>https://www.concretecms.org/about/project-news/security/2023-11-09-security-blog-about-updated-cves-and-new-release</guid>
      <slash:comments>0</slash:comments>
    </item>
    <item>
      <title>Security Advisory 2023-10-31 Concrete CMS rejects CVE-2023-44760 and CVE-2023-44766</title>
      <description><![CDATA[<p><img src="https://www.concretecms.com/application/files/1416/5350/7967/Security_Announcement.png" /></p>Security Advisory 2023-10-31 Concrete CMS rejects CVE-2023-44760 and CVE-2023-44766 ]]></description>
      <pubDate>Tue, 31 Oct 2023 20:01:00 +0000</pubDate>
      <link>https://www.concretecms.org/about/project-news/security/security-advisory-2023-10-31-concrete-cms-rejects-cve-2023-44760-and-cve-2023-44766</link>
      <guid>https://www.concretecms.org/about/project-news/security/security-advisory-2023-10-31-concrete-cms-rejects-cve-2023-44760-and-cve-2023-44766</guid>
      <slash:comments>0</slash:comments>
    </item>
    <item>
      <title>Security Advisory 2023-10-25  Concrete CMS rejects CVE-2023-44763</title>
      <description><![CDATA[<p><img src="https://www.concretecms.com/application/files/1416/5350/7967/Security_Announcement.png" /></p>Concrete CMS is requesting that MITRE close CVE-2023-44763 which was submitted by a community member without the Concrete CMS Team knowledge. ]]></description>
      <pubDate>Wed, 25 Oct 2023 19:57:00 +0000</pubDate>
      <link>https://www.concretecms.org/about/project-news/security/security-advisory-2023-10-25-concrete-cms-rejects-cve-2023-44763</link>
      <guid>https://www.concretecms.org/about/project-news/security/security-advisory-2023-10-25-concrete-cms-rejects-cve-2023-44763</guid>
      <slash:comments>0</slash:comments>
    </item>
    <item>
      <title>Security Advisory 2023-05-15 Disputing NIST score for Concrete CMS CVE-2023-28473</title>
      <description><![CDATA[<p><img src="https://www.concretecms.com/application/files/1416/5350/7967/Security_Announcement.png" /></p>Security Advisory 2023-05-15 Disputing NIST score for Concrete CMS CVE-2023-28473 ]]></description>
      <pubDate>Mon, 15 May 2023 21:54:00 +0000</pubDate>
      <link>https://www.concretecms.org/about/project-news/security/security-advisory-2023-05-15-disputing-nist-score-for-concrete-cms-cve-2023-28473</link>
      <guid>https://www.concretecms.org/about/project-news/security/security-advisory-2023-05-15-disputing-nist-score-for-concrete-cms-cve-2023-28473</guid>
      <slash:comments>0</slash:comments>
    </item>
    <item>
      <title>Concrete CMS Security Advisory 2023-04-20</title>
      <description><![CDATA[<p><img src="https://www.concretecms.com/application/files/1416/5350/7967/Security_Announcement.png" /></p>There have been a number of medium and low security vulnerabilities that have been fixed in version 9 through 9.2. Thanks so much to all the community members who report vulnerabilities following the process outlined on https://www.concretecms.org/security so that they can be triaged and remediated!]]></description>
      <pubDate>Thu, 20 Apr 2023 13:56:00 +0000</pubDate>
      <link>https://www.concretecms.org/about/project-news/security/concrete-cms-security-advisory-2023-04-20</link>
      <guid>https://www.concretecms.org/about/project-news/security/concrete-cms-security-advisory-2023-04-20</guid>
      <slash:comments>0</slash:comments>
    </item>
    <item>
      <title>Concrete CMS Security Advisory 2022-10-31</title>
      <description><![CDATA[<p><img src="https://www.concretecms.com/application/files/1416/5350/7967/Security_Announcement.png" /></p>See the list of newly published Concrete CMS CVEs affecting Concrete CMS below 8.5.10 and 9.0.0 through 9.1.2 which have been fixed with security updates 8.5.10 and 9.1.3
]]></description>
      <pubDate>Mon, 31 Oct 2022 17:36:00 +0000</pubDate>
      <link>https://www.concretecms.org/about/project-news/security/concrete-cms-security-advisory-2022-10-31</link>
      <guid>https://www.concretecms.org/about/project-news/security/concrete-cms-security-advisory-2022-10-31</guid>
      <slash:comments>0</slash:comments>
    </item>
  </channel>
</rss>
