Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-check the state of the account the token had been issued to. The resource server's authorization validator confirmed only that a token existed, had not e
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 5.0.0 ~ 9.5.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85385 | 7.7 HIGH | Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone Field |
| CVE-2026-85386 | 7.3 HIGH | Concrete CMS before 9.5.4 stored is vulneratble to cross-site scripting via unauthenticate |
| CVE-2026-18120 | 6.3 MEDIUM | Missing Authorization in legacy Express entries search endpoint allows disclosure of Expre |
| CVE-2026-87028 | 5.3 MEDIUM | Cross-Board IDOR in the Board Custom Slot Preview in Concrete CMS 9.0.0 through 9.5.3 Disc |
| CVE-2026-87031 | 2.1 LOW | Missing authorization in the REST API user creation endpoint in Concrete CMS 9.2.0 through |
No comments yet