CVE-2026-81922
- EPSS 0.23%
- Veröffentlicht 15.09.2026 18:51:33
- Zuletzt bearbeitet 18.09.2026 15:28:38
Concrete CMS before 9.5.3 did not enforce a per-page authorization check when reordering pages from the sitemap. In the sitemap Explore dashboard controller, the send_to_top and send_to_bottom reorder tasks ran after only a generic sitemap-access che...
CVE-2026-81921
- EPSS 0.21%
- Veröffentlicht 15.09.2026 18:48:52
- Zuletzt bearbeitet 18.09.2026 15:29:38
Concrete CMS 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token grant using the unmodified upstream League grant, which issued new access tokens from a valid refresh token without re-checking the associated account's active status. A user who ob...
CVE-2026-81920
- EPSS 0.19%
- Veröffentlicht 15.09.2026 18:46:30
- Zuletzt bearbeitet 18.09.2026 15:27:27
Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page. The reset() controller action cleared the administrator-configured reserved-word list (concrete.seo.exclude_words) but did not validate th...
CVE-2026-68532
- EPSS 0.19%
- Veröffentlicht 15.09.2026 18:44:33
- Zuletzt bearbeitet 20.09.2026 01:16:29
Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cross-site request forgery. A remote unauthenticated attacker could cause an authenticated user with group type management permissi...
CVE-2026-68533
- EPSS 0.26%
- Veröffentlicht 15.09.2026 18:27:03
- Zuletzt bearbeitet 16.09.2026 19:16:15
Concrete CMS below 9.5.3 conversation attachment uploaded endpoint imported files into the file manager before evaluating the "Add Message Attachments" permission, which was only checked after the file had been stored. A user denied that permission, ...
CVE-2026-68534
- EPSS 0.36%
- Veröffentlicht 15.09.2026 18:25:02
- Zuletzt bearbeitet 16.09.2026 19:16:15
Concrete CMS before 9.5.3 rendered Express entry labels as raw HTML when displaying associated entries, resulting in stored cross-site scripting. An unauthenticated attacker could submit a payload through a public Express Form; it then executed in an...
CVE-2026-81919
- EPSS 0.17%
- Veröffentlicht 15.09.2026 18:22:54
- Zuletzt bearbeitet 18.09.2026 15:26:37
Concrete CMS below 9.5.3 did not validate an anti-CSRF token on the block-arrangement backend endpoint (the arrange() action of Concrete\Controller\Backend\Page\ArrangeBlocks). The action enforced page-edit authorization but performed no token check,...
CVE-2026-81899
- EPSS 0.27%
- Veröffentlicht 15.09.2026 17:54:58
- Zuletzt bearbeitet 16.09.2026 19:16:15
Concrete CMS 9.0.0 to 9.5.2 stored group folder names without sanitization and printed them unescaped on the Members > Groups dashboard page, resulting in stored cross-site scripting. The add and edit group-folder handlers stored the submitted folder...
CVE-2026-18115
- EPSS 0.23%
- Veröffentlicht 15.09.2026 17:39:04
- Zuletzt bearbeitet 16.09.2026 19:16:15
Concrete CMS 9.2.0 to 9.5.2 did not enforce per-field edit_user_properties permissions on the REST API user write endpoints (PUT /ccm/api/1.0/users/{uID} and POST /ccm/api/1.0/users/{uID}/change_password). A user with an update-scoped OAuth token and...
CVE-2026-18113
- EPSS 0.25%
- Veröffentlicht 15.09.2026 17:32:16
- Zuletzt bearbeitet 20.09.2026 01:16:28
In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing them into the page, so a user who could create or rename pages could store a script through a child page name and have it run in t...