在 9.5.3 之前的 Concrete CMS 中,仪表盘的“SEO 排除词”页面存在跨站请求伪造(CSRF)漏洞。 控制器操作会清除管理员配置的保留词列表( ),但它既未验证重置模态框发出的防 CSRF 令牌,也未将请求限制为 POST 方法。远程攻击者若能诱导具有 SEO 访问权限的已认证用户访问精心构造的页面,便可将保留词列表恢复为默认值,从而在未被察觉的情况下更改通过 Text urlify 服务创建的页面、文件、主题及其他对象的未来 URL 别名生成逻辑,进而撤销站点已配置的 SEO 别名策略。Conc
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Concrete CMS | Concrete CMS | 5.0.0≤ 9.5.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 5.0.0 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18110 | 8.7 HIGH | Concrete CMS 9.0.0 through 9.5.2 is vulnerable to missing authorization in the user select |
| CVE-2026-81894 | 8.5 HIGH | Concrete CMS 9.5.2 and below is vulnerable to Stored DOM-based Cross-site Scripting (XSS) |
| CVE-2026-18111 | 8.5 HIGH | Concrete CMS below 9.5.4 allows privilege escalation because adding users and assigning gr |
| CVE-2026-81895 | 8.5 HIGH | Concrete CMS 9.5.2 and below is vulnerable to Stored SQL Injection in Concrete CMS Documen |
| CVE-2026-81896 | 8.4 HIGH | Concrete CMS below version 9.5.3 is vulnerable to Stored XSS in Concrete CMS Form Submissi |
| CVE-2026-81897 | 7.7 HIGH | Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via Express form Text control |
| CVE-2026-81898 | 7.5 HIGH | Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via country-less Address att |
| CVE-2026-18113 | 7.5 HIGH | Concrete CMS 9.0 to 9.5.2 is vulnerable to Stored XSS in the Top Navigation Bar Block via |
| CVE-2026-18115 | 7.4 HIGH | In Concrete CMS 9.2.0 to 9.5.2, Missing Authorization in REST API Users update() and chang |
| CVE-2026-81899 | 7.3 HIGH | Concrete CMS 9.0 to 9.5.2 is vulnerable to Stored XSS via group folder name on the Members |
| CVE-2026-81921 | 2.3 LOW | In Concrete CMS 8.5.3 to 9,5,2, OAuth 2.0 Refresh-Token Grant Bypasses Account Status |
| CVE-2026-68532 | 2.3 LOW | Concrete CMS 9.0.0 to 9.5.2 is vunerable to CSRF in Concrete CMS Group Type Deletion Dashb |
| CVE-2026-68533 | 2.3 LOW | Missing Authorization in Concrete CMS versions below 9.5.3 Conversation File Upload Allows |
| CVE-2026-81919 | 2.3 LOW | Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Block Arran |
| CVE-2026-68534 | 2.3 LOW | Concrete CMS below 9.5.2 is vulnerable to Stored XSS via unescaped Express entry labels in |
| CVE-2026-68531 | 2.1 LOW | Concrete CMS below 9.5.3 is vulnerable to Authenticated Denial of Service via Unescaped SQ |
| CVE-2026-81925 | 2.1 LOW | Concrete CMS below 9.5.3 is vulnerable to Reflected Cross-Site Scripting (XSS) via Convers |
| CVE-2026-18424 | 2.1 LOW | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to SSRF protection bypass in remote file import |
| CVE-2026-18425 | 2.1 LOW | IDOR in Concrete CMS 9.0.0 through 9.5.2 dashboard sitemap reorder (SitemapUpdate::updateD |
| CVE-2026-18422 | 2.1 LOW | Concrete CMS below 9.5.3 Multilingual Page Assign Action Lacks Destination Authorization a |
Showing top 20 of 31 CVEs. View all on vendor page → →
No comments yet