CVE-2020-24986: Concretecms Concrete CMS
High severity, CVSS 7.2. EPSS: 2% chance of exploitation in the next 30 days.
Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File Manager. It is possible to modify site configuration to upload the PHP file and execute arbitrary commands.
Affected products
- Concretecms Concrete CMS: up to and including 8.5.2
Published 2020-09-04. Last modified 2026-06-17.