CVE-2026-18120
- EPSS 0.24%
- Veröffentlicht 16.09.2026 17:16:09
- Zuletzt bearbeitet 21.09.2026 17:51:22
Concrete CMS before 9.5.3 exposed a legacy Express entry search endpoint that returned entry result JSON without invoking the canViewExpressEntries() permission check applied by the normal dashboard and CSV Export flow. An unauthenticated visitor who...
CVE-2026-85387
- EPSS 0.21%
- Veröffentlicht 16.09.2026 17:12:05
- Zuletzt bearbeitet 21.09.2026 17:51:12
Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-check the state of the account the token had been issued to. The resource server's authorization validator confirmed only that a token existed,...
CVE-2026-87031
- EPSS 0.32%
- Veröffentlicht 16.09.2026 16:40:04
- Zuletzt bearbeitet 21.09.2026 17:51:32
n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation endpoint (POST /ccm/api/1.0/users, the add() method of concrete/src/Api/Controller/Users.php) did not perform a permission check before creating an account. As a result, any valid OAuth t...
CVE-2026-87028
- EPSS 0.27%
- Veröffentlicht 16.09.2026 16:36:56
- Zuletzt bearbeitet 21.09.2026 17:51:39
Concrete CMS 9 through 9.5.3 did not confirm that a board InstanceItem submitted to the custom-slot preview endpoint belonged to the board instance the requesting user was authorized to edit, and did not enforce page-view permission before generating...
CVE-2026-85386
- EPSS 0.38%
- Veröffentlicht 16.09.2026 16:33:53
- Zuletzt bearbeitet 21.09.2026 17:51:55
Concrete CMS before 9.5.4 did not sanitize XML and XSLT documents uploaded through a public Form Block file-upload question. Plain XML uploads were validated by file extension only and stored as publicly accessible files that were served inline from ...
CVE-2026-85385
- EPSS 0.43%
- Veröffentlicht 16.09.2026 16:30:28
- Zuletzt bearbeitet 21.09.2026 17:52:41
Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output encoding on the Dashboard user management page, where Date::getTimezoneDisplayName() returns any non-IANA value unchanged. A stored ...
CVE-2026-81927
- EPSS 0.31%
- Veröffentlicht 15.09.2026 20:21:03
- Zuletzt bearbeitet 18.09.2026 15:15:46
Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling. When SVG processing was set to the non-default "Reject files containing potentially harmful elements" mode (concrete.file_manager.images.svg_sanitiz...
CVE-2026-81925
- EPSS 0.37%
- Veröffentlicht 15.09.2026 20:18:04
- Zuletzt bearbeitet 21.09.2026 17:53:13
Concrete CMS before 9.5.3 improperly neutralized a user-supplied custom date format when rendering conversation messages, resulting in reflected cross-site scripting. An attacker could execute arbitrary JavaScript in the browser of a user who was tri...
CVE-2026-18426
- EPSS 0.23%
- Veröffentlicht 15.09.2026 20:16:12
- Zuletzt bearbeitet 21.09.2026 17:53:06
Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level edit-permission check on the Express Form block's control-management actions, which relied solely on CSRF token validation. Because the token is bound to the user and action rather than t...
CVE-2026-81926
- EPSS 0.31%
- Veröffentlicht 15.09.2026 20:14:18
- Zuletzt bearbeitet 21.09.2026 17:53:00
Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's duplicate-path confirmation dialog. The panel's check endpoint returned the submitted path unmodified in its JSON response, and client-...