Concrete CMS 9.5.2 及更早版本中的 Express “清除条目”功能(POST /index.php/dashboard/system/express/entities/delete_entries)存在跨站请求伪造(CSRF)漏洞。原因是控制器在 CSRF 令牌校验失败时仅记录日志而未强制阻断,导致在令牌缺失或无效时,破坏性操作仍会被执行。 远程未认证攻击者可诱使已认证的 administrator 访问其控制的页面,从而强制该管理员永久删除其当前已认证的 Web 应用中、由攻击者指定的某个 E
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 5.0.0 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81908 | 6.0 MEDIUM | Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows |
| CVE-2026-18122 | 6.0 MEDIUM | Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entr |
| CVE-2026-68528 | 6.0 MEDIUM | Concrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Block via Unesca |
| CVE-2026-81909 | 5.9 MEDIUM | Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block |
| CVE-2026-81910 | 5.9 MEDIUM | Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in The |
| CVE-2026-81911 | 5.8 MEDIUM | Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot save |
| CVE-2026-81912 | 5.7 MEDIUM | Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple |
| CVE-2026-81913 | 5.3 MEDIUM | Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL pa |
| CVE-2026-68526 | 5.3 MEDIUM | Concrete CMS before 9.5.3 is vulnerable to CSRF in the Calendar event duplicate dialog con |
| CVE-2026-81915 | 5.1 MEDIUM | In Concrete CMS below 9.5.3, Page Type update omits object-level authorization |
| CVE-2026-81917 | 5.1 MEDIUM | Concrete CMS below 9.5.3 is vulnerable to Stored XSS in the Document Library block file de |
| CVE-2026-81916 | 5.1 MEDIUM | Incorrect Authorization in the Concrete CMS Express Entries Dashboard below version 9.5.3 |
| CVE-2026-68535 | 5.1 MEDIUM | Concrete CMS 9.2.0 to 9.5.2 is vulnerable to Missing authorization in the Concrete CMS Are |
| CVE-2026-81918 | 4.8 MEDIUM | Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page |
No comments yet