以下是该漏洞描述的中文翻译: Concrete CMS 9.5.3 之前的版本在渲染“文档库”(Document Library)区块时,未对文件描述(description)和标签(tags)字段应用 HTML 输出转义。因此,拥有编辑文件属性权限的用户可以存储一段脚本载荷,该载荷将在浏览启用描述或标签列的页面的任何访问者(包括未认证访问者)的浏览器中执行。成功利用此漏洞可能导致会话数据被窃取,或攻击者以访问者的身份执行操作。 具体技术细节:该区块的控制器返回描述和标签的值时,未应用此前已应用于“标题”列的 转义
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 5.0.0 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81907 | 6.1 MEDIUM | Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) vin Expres |
| CVE-2026-81908 | 6.0 MEDIUM | Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows |
| CVE-2026-18122 | 6.0 MEDIUM | Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entr |
| CVE-2026-68528 | 6.0 MEDIUM | Concrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Block via Unesca |
| CVE-2026-81909 | 5.9 MEDIUM | Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block |
| CVE-2026-81910 | 5.9 MEDIUM | Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in The |
| CVE-2026-81911 | 5.8 MEDIUM | Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot save |
| CVE-2026-81912 | 5.7 MEDIUM | Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple |
| CVE-2026-81913 | 5.3 MEDIUM | Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL pa |
| CVE-2026-68526 | 5.3 MEDIUM | Concrete CMS before 9.5.3 is vulnerable to CSRF in the Calendar event duplicate dialog con |
| CVE-2026-81915 | 5.1 MEDIUM | In Concrete CMS below 9.5.3, Page Type update omits object-level authorization |
| CVE-2026-81916 | 5.1 MEDIUM | Incorrect Authorization in the Concrete CMS Express Entries Dashboard below version 9.5.3 |
| CVE-2026-68535 | 5.1 MEDIUM | Concrete CMS 9.2.0 to 9.5.2 is vulnerable to Missing authorization in the Concrete CMS Are |
| CVE-2026-81918 | 4.8 MEDIUM | Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page |
No comments yet