Concrete CMS 在 9.5.3 版本之前存在跨站请求伪造(CSRF)漏洞,受影响的功能是“批量移动组”(Move Multiple Groups)。具体来说, 端点在移动所选的组树节点时,未验证操作令牌(action token),因此攻击者可以诱使一个已认证用户执行其本人并未主动发起的组移动操作,且该状态变更会被服务器处理。 由于将组移动到新的父节点下会导致该组成员继承新父节点的权限,一次伪造的移动操作可能会改变用户的有效授权状态。 Concrete CMS 安全团队为此漏洞分配了 CVSS v4.0
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Concrete CMS | Concrete CMS | 5.0.0≤ 9.5.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 5.0.0 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81908 | 6.0 MEDIUM | Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows |
| CVE-2026-18122 | 6.0 MEDIUM | Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entr |
| CVE-2026-68528 | 6.0 MEDIUM | Concrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Block via Unesca |
| CVE-2026-81909 | 5.9 MEDIUM | Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block |
| CVE-2026-81910 | 5.9 MEDIUM | Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in The |
| CVE-2026-81911 | 5.8 MEDIUM | Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot save |
| CVE-2026-81913 | 5.3 MEDIUM | Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL pa |
| CVE-2026-68526 | 5.3 MEDIUM | Concrete CMS before 9.5.3 is vulnerable to CSRF in the Calendar event duplicate dialog con |
| CVE-2026-81915 | 5.1 MEDIUM | In Concrete CMS below 9.5.3, Page Type update omits object-level authorization |
No comments yet