Concrete CMS 9.5.3 之前的版本在通过站点地图(sitemap)对页面进行重新排序时,未执行针对单个页面的授权检查。在站点地图的“Explore”仪表盘控制器中, 和 这两个重新排序任务仅执行了通用的站点地图访问检查;该控制器会根据攻击者可控的 参数加载对应页面,并在未验证当前用户是否对该特定页面拥有“移动”或“排列”权限的情况下,更改其显示顺序。因此,一个能够访问站点地图但对该页面没有编辑或排列权限的已认证用户,仍然可以移动该页面并更改网站的全局导航顺序。 Concrete CMS 安全团队将此漏
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Concrete CMS | Concrete CMS | 5.0.0≤ 9.5.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 5.0.0 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18110 | 8.7 HIGH | Concrete CMS 9.0.0 through 9.5.2 is vulnerable to missing authorization in the user select |
| CVE-2026-81894 | 8.5 HIGH | Concrete CMS 9.5.2 and below is vulnerable to Stored DOM-based Cross-site Scripting (XSS) |
| CVE-2026-18111 | 8.5 HIGH | Concrete CMS below 9.5.4 allows privilege escalation because adding users and assigning gr |
| CVE-2026-81895 | 8.5 HIGH | Concrete CMS 9.5.2 and below is vulnerable to Stored SQL Injection in Concrete CMS Documen |
| CVE-2026-81896 | 8.4 HIGH | Concrete CMS below version 9.5.3 is vulnerable to Stored XSS in Concrete CMS Form Submissi |
| CVE-2026-81897 | 7.7 HIGH | Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via Express form Text control |
| CVE-2026-81898 | 7.5 HIGH | Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via country-less Address att |
| CVE-2026-18113 | 7.5 HIGH | Concrete CMS 9.0 to 9.5.2 is vulnerable to Stored XSS in the Top Navigation Bar Block via |
| CVE-2026-18115 | 7.4 HIGH | In Concrete CMS 9.2.0 to 9.5.2, Missing Authorization in REST API Users update() and chang |
| CVE-2026-81899 | 7.3 HIGH | Concrete CMS 9.0 to 9.5.2 is vulnerable to Stored XSS via group folder name on the Members |
| CVE-2026-81921 | 2.3 LOW | In Concrete CMS 8.5.3 to 9,5,2, OAuth 2.0 Refresh-Token Grant Bypasses Account Status |
| CVE-2026-81920 | 2.3 LOW | Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Dashboard S |
| CVE-2026-68532 | 2.3 LOW | Concrete CMS 9.0.0 to 9.5.2 is vunerable to CSRF in Concrete CMS Group Type Deletion Dashb |
| CVE-2026-68533 | 2.3 LOW | Missing Authorization in Concrete CMS versions below 9.5.3 Conversation File Upload Allows |
| CVE-2026-81919 | 2.3 LOW | Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Block Arran |
| CVE-2026-68534 | 2.3 LOW | Concrete CMS below 9.5.2 is vulnerable to Stored XSS via unescaped Express entry labels in |
| CVE-2026-68531 | 2.1 LOW | Concrete CMS below 9.5.3 is vulnerable to Authenticated Denial of Service via Unescaped SQ |
| CVE-2026-81925 | 2.1 LOW | Concrete CMS below 9.5.3 is vulnerable to Reflected Cross-Site Scripting (XSS) via Convers |
| CVE-2026-18424 | 2.1 LOW | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to SSRF protection bypass in remote file import |
| CVE-2026-18425 | 2.1 LOW | IDOR in Concrete CMS 9.0.0 through 9.5.2 dashboard sitemap reorder (SitemapUpdate::updateD |
Showing top 20 of 31 CVEs. View all on vendor page → →
No comments yet