Concrete CMS 在 9.5.3 版本之前,在评估 Express 条目提交的授权检查时,是相对于所提交表单的实体,而非仪表盘路由所识别的实体进行判断的。因此,一个被允许向某个 Express 对象添加条目的用户,可以在其授权范围之外的另一个 Express 对象中创建条目,从而可能污染受保护的数据集、触发工作流,或将内容注入到管理流程中。具体机制是:仪表盘提交路由从攻击者可控的路由 ID 解析出被变更的实体,而权限检查则验证了独立提交的表单的实体,由于这两个实体从未被相互比较,提交得以成功执行。Concr
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 5.0.0 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81907 | 6.1 MEDIUM | Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) vin Expres |
| CVE-2026-81908 | 6.0 MEDIUM | Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows |
| CVE-2026-18122 | 6.0 MEDIUM | Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entr |
| CVE-2026-68528 | 6.0 MEDIUM | Concrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Block via Unesca |
| CVE-2026-81909 | 5.9 MEDIUM | Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block |
| CVE-2026-81910 | 5.9 MEDIUM | Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in The |
| CVE-2026-81911 | 5.8 MEDIUM | Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot save |
| CVE-2026-81912 | 5.7 MEDIUM | Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple |
| CVE-2026-81913 | 5.3 MEDIUM | Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL pa |
| CVE-2026-68526 | 5.3 MEDIUM | Concrete CMS before 9.5.3 is vulnerable to CSRF in the Calendar event duplicate dialog con |
| CVE-2026-81915 | 5.1 MEDIUM | In Concrete CMS below 9.5.3, Page Type update omits object-level authorization |
| CVE-2026-81917 | 5.1 MEDIUM | Concrete CMS below 9.5.3 is vulnerable to Stored XSS in the Document Library block file de |
| CVE-2026-68535 | 5.1 MEDIUM | Concrete CMS 9.2.0 to 9.5.2 is vulnerable to Missing authorization in the Concrete CMS Are |
| CVE-2026-81918 | 4.8 MEDIUM | Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page |
No comments yet