CVE-2026-68526
- EPSS 0.17%
- Veröffentlicht 11.09.2026 19:35:37
- Zuletzt bearbeitet 25.09.2026 20:41:17
Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/controllers/dialog/event/duplicate.php) submit() action, which duplicated a calendar event after checking only canAccess() and t...
CVE-2026-81913
- EPSS 0.52%
- Veröffentlicht 11.09.2026 19:30:50
- Zuletzt bearbeitet 24.09.2026 20:13:27
Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. An attacker can craft a single link on the site's own domain that sends a user to an arbitrary external site immediately after authentication, facilita...
CVE-2026-81912
- EPSS 0.16%
- Veröffentlicht 11.09.2026 19:27:49
- Zuletzt bearbeitet 24.09.2026 20:18:47
Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature. The dashboard/users/groups/bulkupdate/confirm() endpoint moved the selected group tree nodes without validating an action token, so a state-cha...
CVE-2026-81911
- EPSS 0.3%
- Veröffentlicht 11.09.2026 19:24:05
- Zuletzt bearbeitet 18.09.2026 19:00:06
Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot dialog. The custom_slot save_template endpoint authorizes the request only against the target board instance (canEditBoardContents()) and then persists the client-s...
CVE-2026-81910
- EPSS 0.25%
- Veröffentlicht 11.09.2026 18:20:25
- Zuletzt bearbeitet 16.09.2026 17:40:45
Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values. Values submitted through the customizer (color channels and other style properties handled by ColorStyle and sibling...
CVE-2026-81909
- EPSS 0.23%
- Veröffentlicht 11.09.2026 17:49:47
- Zuletzt bearbeitet 11.09.2026 18:22:06
Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the block alias route (Process::alias() in concrete/controllers/backend/block/process.php).It does not verify that the referenced block is genuinely orphaned on the target page, n...
- EPSS 0.21%
- Veröffentlicht 11.09.2026 17:34:55
- Zuletzt bearbeitet 11.09.2026 20:17:22
Concrete CMS RSS Displayer block below version 9.5.3 rendered remote feed item titles without HTML escaping, resulting in stored cross-site scripting. An attacker able to control a title in a syndicated feed could execute script in the site origin f...
- EPSS 0.21%
- Veröffentlicht 11.09.2026 17:15:14
- Zuletzt bearbeitet 11.09.2026 20:17:12
Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization; the Concrete CMS REST API's Express entry collection endpoint disabled the per-entry view permission check. An OAuth token with r...
- EPSS 0.21%
- Veröffentlicht 11.09.2026 17:09:46
- Zuletzt bearbeitet 11.09.2026 20:19:13
Concrete CMS 9.2.0 to 9.5.2 contain a missing authorization vulnerability in the REST API Groups list endpoint. The listGroups() method in concrete/src/Api/Controller/Groups.php registers a permissions checker callback that unconditionally returns tr...
CVE-2026-81906
- EPSS 0.34%
- Veröffentlicht 10.09.2026 23:20:47
- Zuletzt bearbeitet 11.09.2026 15:17:06
Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete authentication...