CVE-2026-18425
- EPSS 0.16%
- Veröffentlicht 15.09.2026 19:52:04
- Zuletzt bearbeitet 21.09.2026 17:51:00
Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap reorder action (Concrete\Controller\Backend\Dashboard\SitemapUpdate) using only the global access_sitemap task permission and did not check per-page edit permission before updating each pag...
CVE-2026-18424
- EPSS 0.29%
- Veröffentlicht 15.09.2026 19:49:48
- Zuletzt bearbeitet 21.09.2026 17:50:50
Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side Request Forgery iremote file import via cross-port reuse of a host's validated DNS pin. When multiple remote URLs share the same host, only the first `ValidatedRemoteUrl` is retained and reused...
CVE-2026-18423
- EPSS 0.28%
- Veröffentlicht 15.09.2026 19:30:13
- Zuletzt bearbeitet 21.09.2026 17:50:42
Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs . An authenticated user holding only view permission on a single Express entity could therefore perm...
CVE-2026-18422
- EPSS 0.37%
- Veröffentlicht 15.09.2026 19:27:59
- Zuletzt bearbeitet 21.09.2026 17:50:08
Concrete CMS before 9.5.3 did not enforce a destination-side authorization check and did not validate a CSRF token in the multilingual page assignment backend action (Backend\Page\Multilingual::assign). As a result, an authenticated user who held the...
CVE-2026-68529
- EPSS 0.24%
- Veröffentlicht 15.09.2026 19:17:36
- Zuletzt bearbeitet 16.09.2026 19:16:15
Concrete CMS 9.0.0 through 9.5.2 was missing an authorization check on the Express entries advanced-search dashboard action. The advanced_search() method in DashboardSelectableExpressEntryListTrait resolved an Express entity directly from a user-supp...
CVE-2026-68530
- EPSS 0.25%
- Veröffentlicht 15.09.2026 19:17:36
- Zuletzt bearbeitet 16.09.2026 19:16:15
Concrete CMS 9 through 9.5.2 did not perform an authorization check on several board-instance actions in the Boards area of the Dashboard. The instance details single-page controller resolved a board instance directly from an attacker-supplied instan...
CVE-2026-68531
- EPSS 0.25%
- Veröffentlicht 15.09.2026 19:17:36
- Zuletzt bearbeitet 16.09.2026 19:16:15
Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard characters in the keyword search filters used by the file manager, file folders, and page list, allowing an authenticated user with editor-level or higher privileges to submit a crafted sea...
CVE-2026-18421
- EPSS 0.24%
- Veröffentlicht 15.09.2026 19:17:17
- Zuletzt bearbeitet 16.09.2026 19:16:15
Concrete CMS 9 through 9.5.2 does not perform an authorization check in three actions of the Boards data source dashboard controller (update, update_data_source, and delete_data_source), which resolve a ConfiguredDataSource directly from an attacker-...
CVE-2026-81924
- EPSS 0.18%
- Veröffentlicht 15.09.2026 18:55:57
- Zuletzt bearbeitet 21.09.2026 17:50:00
Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in the theme page-template activation feature. The Dashboard theme Inspect controller's activate_files() action created PageTemplate records from attacker-supplied pageTempl...
CVE-2026-81923
- EPSS 0.23%
- Veröffentlicht 15.09.2026 18:53:26
- Zuletzt bearbeitet 18.09.2026 15:28:11
In Concrete CMS before 9.5.3, the SEO Bulk Update Meta Tags editor did not check per-page edit permissions before saving. The saveRecord() action validated the per-page CSRF token but never called canEditPageProperties() for the target page, so a use...