Concrete CMS 9 至 9.5.3 版本未能验证提交到自定义插槽预览端点的 board InstanceItem 是否属于请求用户有权编辑的 board 实例,也未在生成基于页面的摘要内容之前强制执行页面查看权限。因此,拥有单个 board 实例“编辑 board 内容”权限的已认证用户,可以提交一个属于不同 board 实例的项目标识符,并获取该用户本无权查看的底层页面的摘要字段,包括页面标题和描述。 Concrete CMS 安全团队为该漏洞分配的 CVSS v4.0 评分为 5.3,向量字符串为 C
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 9.0.0 ~ 9.5.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85385 | 7.7 HIGH | Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone Field |
| CVE-2026-85386 | 7.3 HIGH | Concrete CMS before 9.5.4 stored is vulneratble to cross-site scripting via unauthenticate |
| CVE-2026-18120 | 6.3 MEDIUM | Missing Authorization in legacy Express entries search endpoint allows disclosure of Expre |
| CVE-2026-87031 | 2.1 LOW | Missing authorization in the REST API user creation endpoint in Concrete CMS 9.2.0 through |
| CVE-2026-85387 | 2.0 LOW | Concrete CMS before 9.5.4 allows a deactivated user to retain OAuth-authenticated REST API |
No comments yet