Concrete CMS 9 至 9.5.2 版本在未对“孤立区块移除”面板操作(removeOrphanedBlocks)验证 CSRF 令牌的情况下,存在漏洞。远程攻击者可构造请求,当该请求被拥有目标页面编辑权限的已认证用户加载时,会删除该页面当前版本中的所有区块;未被别名关联到其他页面或剪贴本条目的区块,还会从全局 Blocks 表及其区块类型数据表中被移除,从而永久性销毁内容。Concrete CMS 安全团队将此漏洞的 CVSS v4.0 评分定为 7.1,其向量为:CVSS:4.0/AV:N/AC:L/
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 9.0.0 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18117 | 7.3 HIGH | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Custom Page Alias Name |
| CVE-2026-81900 | 7.3 HIGH | Concrete CMS before 9.5.3 is vulnerable to Stored XSS in the YouTube block (vWidth/vHeight |
| CVE-2026-18116 | 7.3 HIGH | Concrete CMS 8.3.0 to 9.5.2 is vulnerable to Stored XSS in Calendar Event Name via Workflo |
| CVE-2026-81901 | 7.2 HIGH | Concrete CMS 9.2.0 to 9.5.2 is vulnerable to stored XSS due to missing authorization in th |
| CVE-2026-18119 | 7.0 HIGH | Concrete CMS below 9.5.3 is vulnerable to Stored XSS via unsanitized inline block custom s |
| CVE-2026-81903 | 7.0 HIGH | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS via Page Container icon |
No comments yet