Concrete CMS 9.5.4 之前的版本在写入时未对用户时区值( )进行验证,并且在仪表板(Dashboard)的用户管理页面上未对其输出进行编码即直接渲染。在此场景下, 方法会原样返回任何非 IANA 标准的时区值。攻击者可将存储型跨站脚本(Stored XSS)载荷写入该字段,当管理员在仪表板中查看受影响的该用户时,恶意脚本将在管理员的浏览器中执行,从而在管理员会话中运行脚本(例如:读取 CSRF 令牌、创建管理员账户或修改站点设置)。 在 Concrete CMS 9.5.3 中,由于启用了公共注册功
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 5.0.0 ~ 9.5.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85386 | 7.3 HIGH | Concrete CMS before 9.5.4 stored is vulneratble to cross-site scripting via unauthenticate |
| CVE-2026-18120 | 6.3 MEDIUM | Missing Authorization in legacy Express entries search endpoint allows disclosure of Expre |
| CVE-2026-87028 | 5.3 MEDIUM | Cross-Board IDOR in the Board Custom Slot Preview in Concrete CMS 9.0.0 through 9.5.3 Disc |
| CVE-2026-87031 | 2.1 LOW | Missing authorization in the REST API user creation endpoint in Concrete CMS 9.2.0 through |
| CVE-2026-85387 | 2.0 LOW | Concrete CMS before 9.5.4 allows a deactivated user to retain OAuth-authenticated REST API |
No comments yet