Concrete CMS 在 9.5.3 之前的版本中,其 Feature(特色展示)、Feature Link(特色链接)、Hero Image(主图)和 Image(图片)区块存在存储型跨站脚本攻击(Stored XSS)漏洞;在 8.5.21 之前的 Concrete 8 版本中,Feature 和 Image 区块同样存在该漏洞。其根本原因在于:外部链接的 URL 未得到链接过滤器的充分验证,且在渲染时未进行输出转义。 拥有页面编辑权限的用户(例如同时具备“添加区块”和“编辑内容”权限的用户)可以通过构造特
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 9.0.0 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18110 | 8.7 HIGH | Concrete CMS 9.0.0 through 9.5.2 is vulnerable to missing authorization in the user select |
| CVE-2026-81895 | 8.5 HIGH | Concrete CMS 9.5.2 and below is vulnerable to Stored SQL Injection in Concrete CMS Documen |
| CVE-2026-81894 | 8.5 HIGH | Concrete CMS 9.5.2 and below is vulnerable to Stored DOM-based Cross-site Scripting (XSS) |
| CVE-2026-81896 | 8.4 HIGH | Concrete CMS below version 9.5.3 is vulnerable to Stored XSS in Concrete CMS Form Submissi |
| CVE-2026-81897 | 7.7 HIGH | Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via Express form Text control |
| CVE-2026-81898 | 7.5 HIGH | Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via country-less Address att |
| CVE-2026-18113 | 7.5 HIGH | Concrete CMS 9.0 to 9.5.2 is vulnerable to Stored XSS in the Top Navigation Bar Block via |
| CVE-2026-18115 | 7.4 HIGH | In Concrete CMS 9.2.0 to 9.5.2, Missing Authorization in REST API Users update() and chang |
| CVE-2026-81899 | 7.3 HIGH | Concrete CMS 9.0 to 9.5.2 is vulnerable to Stored XSS via group folder name on the Members |
| CVE-2026-81919 | 2.3 LOW | Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Block Arran |
| CVE-2026-68533 | 2.3 LOW | Missing Authorization in Concrete CMS versions below 9.5.3 Conversation File Upload Allows |
| CVE-2026-68534 | 2.3 LOW | Concrete CMS below 9.5.2 is vulnerable to Stored XSS via unescaped Express entry labels in |
| CVE-2026-68532 | 2.3 LOW | Concrete CMS 9.0.0 to 9.5.2 is vunerable to CSRF in Concrete CMS Group Type Deletion Dashb |
| CVE-2026-81920 | 2.3 LOW | Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Dashboard S |
| CVE-2026-81921 | 2.3 LOW | In Concrete CMS 8.5.3 to 9,5,2, OAuth 2.0 Refresh-Token Grant Bypasses Account Status |
| CVE-2026-81922 | 2.1 LOW | "In Concrete CMS below 9.5.3, there is Missing authorization in the sitemap page reorder a |
No comments yet