Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-81910— Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values

Quick assessment

Affected
Concrete CMS Concrete CMS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Concrete CMS 9 至 9.5.2 版本中的主题定制器存在服务器端模板注入(SSTI)漏洞,原因是未对样式值进行验证。通过定制器提交的值(包括颜色通道及其他由 及类似 、 等样式类处理的样式属性)在未经 LESS 语法中性化(即未对特殊字符进行转义或过滤)的情况下,直接插值到服务器端编译的 LESS 源代码中,这使得拥有“主题定制”权限的用户可以注入任意的 LESS 指令。 通过注入 指令,攻击者可以读取服务器上的任意文件,并通过 PHP 流包装器访问内部网络资源。编译后的输出结果(包括任何被披露的文件内

CVSS 5.9 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81910

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values
Source: CVE Program / CVE List V5
Vulnerability Description
Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values. Values submitted through the customizer (color channels and other style properties handled by ColorStyle and sibling Style classes such as FontFamilyStyle and ImageStyle) are interpolated into server-compiled LESS source without neutralization of LESS syntax, allowing a user with the Theme Customization permission to inject arbitrary LESS directives. By injecting the @import (inline) directive, an attacker can read arbitrary files on the server and reach internal network resources through PHP stream wrappers. The compiled output, including any disclosed file contents, is written to the site's publicly served CSS cache, exposing database credentials, private keys, and other application secrets, and enabling server-side request forgery. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.9 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1336
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Concrete CMS Concrete CMS 9.0.0 ~ 9.5.2 -

II. Public POCs for CVE-2026-81910

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81910

登录查看更多情报信息。

Vendor Pages for CVE-2026-81910 (1)

Same Patch Batch · Concrete CMS · 2026-09-11 · 5 CVEs total

CVE-2026-81908 6.0 MEDIUM Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows
CVE-2026-18122 6.0 MEDIUM Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entr
CVE-2026-68528 6.0 MEDIUM Concrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Block via Unesca
CVE-2026-81909 5.9 MEDIUM Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block

IV. Related Vulnerabilities

V. Comments for CVE-2026-81910

No comments yet


Leave a comment