Concrete CMS 9.2.0 至 9.5.2 版本中,Express REST API 的列表端点因缺少授权检查,导致受限的 Express 条目暴露出来。具体而言,Concrete CMS 的 REST API 中 Express 条目集合端点禁用了针对单个条目的查看权限检查。因此,仅具有 Express 实体读取范围的 OAuth 令牌,能够枚举其用户上下文本无权查看的条目,从而泄露每条条目的公开标识符、URL、标签、日期,以及通过 参数请求的任意属性或关联条目数据。 Concrete CMS 安全团队
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 9.2.0 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81908 | 6.0 MEDIUM | Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows |
| CVE-2026-68528 | 6.0 MEDIUM | Concrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Block via Unesca |
| CVE-2026-81909 | 5.9 MEDIUM | Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block |
| CVE-2026-81910 | 5.9 MEDIUM | Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in The |
No comments yet