Concrete CMS 区域 API(Area API)的 block-create 端点在 9.2.0 至 9.5.2 版本中,未对提交的数据调用区块类型控制器的 方法。对于涉及文件引用的区块(如 和 ),该 方法正是用于将所引用的文件与用户的文件管理器可见性策略进行授权校验的地方。 由于这一缺失,拥有 block-add 权限范围的已认证用户可以保存并导致页面渲染出指向某个文件的引用,而该文件本应被文件管理器授权策略拒绝。这会导致该文件的 URL 及其预览图向编辑者以及访问受影响页面的访客披露。 在公共文件存
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 9.2.0 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81907 | 6.1 MEDIUM | Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) vin Expres |
| CVE-2026-81908 | 6.0 MEDIUM | Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows |
| CVE-2026-18122 | 6.0 MEDIUM | Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entr |
| CVE-2026-68528 | 6.0 MEDIUM | Concrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Block via Unesca |
| CVE-2026-81909 | 5.9 MEDIUM | Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block |
| CVE-2026-81910 | 5.9 MEDIUM | Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in The |
| CVE-2026-81911 | 5.8 MEDIUM | Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot save |
| CVE-2026-81912 | 5.7 MEDIUM | Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple |
| CVE-2026-81913 | 5.3 MEDIUM | Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL pa |
| CVE-2026-68526 | 5.3 MEDIUM | Concrete CMS before 9.5.3 is vulnerable to CSRF in the Calendar event duplicate dialog con |
| CVE-2026-81915 | 5.1 MEDIUM | In Concrete CMS below 9.5.3, Page Type update omits object-level authorization |
| CVE-2026-81917 | 5.1 MEDIUM | Concrete CMS below 9.5.3 is vulnerable to Stored XSS in the Document Library block file de |
| CVE-2026-81916 | 5.1 MEDIUM | Incorrect Authorization in the Concrete CMS Express Entries Dashboard below version 9.5.3 |
| CVE-2026-81918 | 4.8 MEDIUM | Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page |
No comments yet