Concrete CMS 9.5.4 之前的版本未对通过公共表单块(Form Block)文件上传问题点上传的 XML 和 XSLT 文档进行有效消毒处理。纯 XML 文件上传仅基于文件扩展名进行验证,并被存储为可从应用程序自身源(origin)内联访问的公开文件。因此,未经身份验证的访客可以存储一个包含 处理指令的 XML 文档,该指令引用由攻击者提供的、同源(same-origin)的 XSLT 样式表。当受害者直接在浏览器中打开该存储的文件时,浏览器会获取该样式表,将文档转换为 HTML,并在 Concret
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 5.0.0 ~ 9.5.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85385 | 7.7 HIGH | Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone Field |
| CVE-2026-18120 | 6.3 MEDIUM | Missing Authorization in legacy Express entries search endpoint allows disclosure of Expre |
| CVE-2026-87028 | 5.3 MEDIUM | Cross-Board IDOR in the Board Custom Slot Preview in Concrete CMS 9.0.0 through 9.5.3 Disc |
| CVE-2026-87031 | 2.1 LOW | Missing authorization in the REST API user creation endpoint in Concrete CMS 9.2.0 through |
| CVE-2026-85387 | 2.0 LOW | Concrete CMS before 9.5.4 allows a deactivated user to retain OAuth-authenticated REST API |
No comments yet