以下是该漏洞描述的中文翻译: 在 9.5.3 版本之前的 Concrete CMS RSS 显示块(RSS Displayer block)在渲染远程源站(syndicated feed)条目标题时,未进行 HTML 转义处理,从而导致了存储型跨站脚本(Stored XSS)漏洞。 如果攻击者能够控制某个聚合源站中的条目标题,就可以向访问受影响页面的任何访客(包括管理员)的浏览器中执行脚本代码,且攻击者无需在该网站拥有账号。 Concrete CMS 安全团队为该漏洞分配了 CVSS v4.0 评分 6.0,向量字
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 5.0.0 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81908 | 6.0 MEDIUM | Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows |
| CVE-2026-18122 | 6.0 MEDIUM | Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entr |
| CVE-2026-81909 | 5.9 MEDIUM | Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block |
No comments yet