Concrete CMS 9 至 9.5.2 版本存在缺失授权(Missing Authorization)漏洞,位于区块别名路由( ,位于 )中。 该路由未能验证所引用的区块在目标页面上是否确为“孤立”状态,也未能验证调用者是否对源区块拥有任何权限。因此,一个仅被授予自己页面上“向指定区域添加区块”(area-scoped add_block_to_area)委托权限的用户,可以传入站点内任意区块 ID。结果,源区块的内容会被复制到一个由该非授权编辑者可控制的区域中,从而泄露该内容;同时,原始区块会在同一请求中被
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 9.0.0 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81908 | 6.0 MEDIUM | Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows |
| CVE-2026-18122 | 6.0 MEDIUM | Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entr |
| CVE-2026-68528 | 6.0 MEDIUM | Concrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Block via Unesca |
| CVE-2026-81910 | 5.9 MEDIUM | Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in The |
No comments yet