There is a flaw in Concrete5 CMS prior to version 8.5.6 which means hackers can gain control of your website and any personal data held within it.
This vulnerability within Concrete5 which it can potentially be hacked. The good news is that v8.5.6 of Concrete5 has been released to address this vulnerability and we recommend all clients update to it asap.
According to SecurityAffairs.co, the specific version targeted is v8.5.2
Unfortunately, not doing this update means that the site could be hacked which would take it over, add malicious code even take it down. There could also be a leak of personal details or other data, so this is a very serious situation.
The cleanup process can potentially then be difficult and expensive, because you would need to find all of the malicious code and any added files that the hackers place around the site.
Rest assured Concrete5 remains an excellent platform with a good level of security. If websites are kept up to date, a Concrete5 website can last a very long time with only very minimal, occasional updates.
Therefore prevention is much better than cure in this case, so we recommend updating to 8.5.6+ as soon as possible. We are working through our clients sites updating them. If you need help updating your website please get in touch as soon as possible using the details below:
What's next?
Contact us for a friendly, no-obligation chat about your project...
Call free
0800 111 4504
Article by David Reeder. LinkedIn Profile: https://www.linkedin.com/in/david-e-reeder/
Related Articles
29 August 2025
A while ago, Concrete CMS introduced folders as a way of organising related files. What if we could make a block that lists all the files in a folder… Read more
09 July 2025
Concrete CMS comes with very flexible, granular user permissions. When setting permissions to advanced, we can give users access to edit as much or… Read more
16 October 2024
Caching is essential for making web pages load fast, but you also need an acceptable level of control to avoid other issues. Concrete CMS features a… Read more
Keep up to date
Subscribe to receive occasional email newsletters from us.