Concrete CMS 9.5.0 至 9.5.2 版本中的 参数存在开放重定向漏洞。攻击者可以构造一个位于网站自身域名下的单一链接,使用户在认证后立即被重定向到任意外部站点,从而便于实施钓鱼攻击和凭证窃取。在启用了注册功能的站点上,注册流程中采用了相同的处理逻辑,提供了第二个入口点。Concrete CMS 9.5.0 之前的版本不包含 参数或相关白名单机制,因此不受该漏洞影响。Concrete CMS 安全团队为此漏洞赋予的 CVSS v4.0 得分为 5.3,向量表示为 CVSS:4.0/AV:N/AC:L
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Concrete CMS | Concrete CMS | 9.5.0≤ 9.5.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 9.5.0 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81908 | 6.0 MEDIUM | Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows |
| CVE-2026-18122 | 6.0 MEDIUM | Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entr |
| CVE-2026-68528 | 6.0 MEDIUM | Concrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Block via Unesca |
| CVE-2026-81909 | 5.9 MEDIUM | Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block |
| CVE-2026-81910 | 5.9 MEDIUM | Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in The |
| CVE-2026-81911 | 5.8 MEDIUM | Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot save |
| CVE-2026-81912 | 5.7 MEDIUM | Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple |
| CVE-2026-68526 | 5.3 MEDIUM | Concrete CMS before 9.5.3 is vulnerable to CSRF in the Calendar event duplicate dialog con |
| CVE-2026-81915 | 5.1 MEDIUM | In Concrete CMS below 9.5.3, Page Type update omits object-level authorization |
No comments yet