These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A vulnerability in Concrete CMS before version 9.5.4 allows deactivated or deleted users to retain access to certain API endpoints due to inadequate re-authorization checks. The CVSS v4.0 score is 2.0, indicating a low severity. This issue arises from the CMS's failure to properly re-authorize OAuth REST API requests, allowing users with deactivated or deleted accounts to retain access to specific endpoin [truncated]
A vulnerability in Concrete CMS before version 9.5.3 allows unauthenticated visitors to enumerate entry search results for Express entities, potentially disclosing restricted attribute values. The issue arises from an exposed legacy Express entry search endpoint that does not invoke the canViewExpressEntries() permission check. This CVE has been assigned a CVSS v4.0 score of 6.3, indicating a medium severity level.
A vulnerability in Concrete CMS 9.2.0 through 9.5.3 allows for the creation of active, validated user accounts without proper permission checks, potentially leading to stored cross-site scripting. This issue arises from the REST API user creation endpoint's failure to perform necessary permission checks before creating an account. As a result, any valid OAuth token carrying the users:add scope can be expl [truncated]
An authenticated user with edit-board-contents permission on a single board instance in Concrete CMS 9 through 9.5.3 could submit an item identifier from a different board instance and receive summary fields of an underlying page they were not authorized to view. The vulnerability, scored 5.3 by the Concrete CMS security team, allows unauthorized information disclosure. Defenders should assess exposure, p [truncated]
A vulnerability in Concrete CMS before version 9.5.4 allows unauthenticated visitors to store malicious XML documents containing xml-stylesheet processing instructions that reference attacker-supplied XSLT stylesheets. When a victim opens the stored file directly in a browser, the browser fetches the stylesheet, transforms the document into HTML, and executes attacker-controlled JavaScript in the Concrete [truncated]
A stored cross-site scripting vulnerability exists in Concrete CMS versions below 9.5.4. An attacker can save a malicious payload in the user timezone field, which is then executed in an administrator's browser when they view the affected user in the Dashboard. The vulnerability requires the concrete.misc.user_timezones feature to be enabled and, in Concrete CMS 9.5.3, public registration to be enabled.
A stored cross-site scripting vulnerability exists in Concrete CMS before version 9.5.3, specifically in the handling of SVG files. When SVG processing is set to reject files containing potentially harmful elements, uploaded SVGs are only checked against a limited blocklist. This allows a user with file upload capabilities to execute arbitrary JavaScript in the browser of any user who views the file directly.
A low-severity vulnerability in Concrete CMS 9.4.0 through 9.5.2 allows an authenticated attacker to execute script in the editor's browser session via a crafted page path in the location panel's duplicate-path confirmation dialog. The vulnerability requires an authenticated user with high privileges to exploit, limiting its impact. Defenders should assess exposure and apply patches or workarounds to prev [truncated]
A low-severity vulnerability in Concrete CMS 9.0.0 through 9.5.2 allows an authenticated user with edit access to one Express Form to add, modify, or delete controls on Express Forms they are not authorized to edit, potentially leading to stored XSS. The vulnerability arises from the Express Form block's failure to enforce a block-level edit-permission check on control-management actions, relying solely o [truncated]
A low-severity vulnerability was found in Concrete CMS before version 9.5.3, where user-supplied custom date formats were not properly neutralized when rendering conversation messages. This could lead to reflected cross-site scripting (XSS). An attacker could exploit this by tricking a user into submitting a crafted POST request to the conversation view endpoint, which lacked a CSRF token, allowing for cr [truncated]
An authenticated user with sitemap access could reorder pages they were not authorized to edit in Concrete CMS 9 before 9.5.3, due to insufficient permission checks in the dashboard sitemap reorder action. This could alter navigation, breadcrumb, and page-list output. The action also lacked CSRF token validation, allowing forged requests to trigger the write operation.
A low-privileged authenticated user in Concrete CMS 9.0.0 to 9.5.2 can exploit a Server-Side Request Forgery (SSRF) vulnerability via cross-port reuse of a host's validated DNS pin, allowing them to import files and potentially access internal resources. This vulnerability enables an attacker to supply a DNS-rebinding host that resolves to a public address during validation and to a private or loopback ad [truncated]
A low-severity vulnerability was found in Concrete CMS versions 9.0.0 through 9.5.2, allowing an authenticated user with view permission on a single Express entity to delete or rename saved search presets owned by other entities. This could potentially enable defacement or social engineering. The vulnerability, caused by an Insecure Direct Object Reference (IDOR) in the Express saved search preset delete [truncated]
A low-severity vulnerability in Concrete CMS before version 9.5.3 allows an authenticated user with Edit Page Multilingual Settings permission to bind an arbitrary page in another locale as a translation and delete legitimate translation pairs, altering public-facing language routing. The CVSS v4.0 score is 2.1. This issue arises from insufficient authorization checks and lack of CSRF token validation in [truncated]
A Cross-Site Request Forgery (CSRF) vulnerability exists in Concrete CMS before version 9.5.3. The vulnerability is located in the theme page-template activation feature. An attacker could exploit this by hosting a page that auto-submits a forged POST request. When a signed-in administrator visits the page, the request executes under the administrator's session, creating theme page-template records and ch [truncated]
A low-severity vulnerability in Concrete CMS before version 9.5.3 allows users with bulk SEO tool access and view-only permissions to modify meta tags and URLs of pages they cannot edit. This could potentially impact content presentation and live URLs. The issue arises from the SEO Bulk Update Meta Tags editor not checking per-page edit permissions before saving changes. Affected deployments should verify [truncated]
An authenticated user with limited permissions could reorder pages in Concrete CMS before 9.5.3, altering the site's navigation order, due to a missing per-page authorization check in the sitemap Explore dashboard controller. This oversight allowed unauthorized changes to the site's structure, potentially impacting site integrity and user experience. Site administrators should verify user permissions and [truncated]
A vulnerability in Concrete CMS 8.5.3 through 9.5.2 allows a user to continue minting valid access tokens after being deactivated or suspended due to the OAuth 2.0 refresh-token grant being enabled without re-checking the associated account's active status. This issue arises because the upstream League grant was used without modification, leading to a situation where deactivating an account does not revok [truncated]
A Cross-Site Request Forgery vulnerability in Concrete CMS below 9.5.3 allows a remote attacker to revert the administrator-configured reserved-word list and alter future URL-slug generation. This issue, reported by riodrwn, was scored 2.3 by the Concrete CMS security team with a CVSS v4.0 vector of CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N.
A low-severity vulnerability was found in Concrete CMS versions below 9.5.3. An attacker could exploit the block-arrangement backend endpoint to reorder or move blocks in a draft page without proper validation of an anti-CSRF token. This oversight allowed unauthorized changes to page layouts by inducing signed-in content editors into performing unintended actions. The vulnerability was publicly disclosed [truncated]
A low-severity vulnerability was found in Concrete CMS versions 9.0.0, where the dashboard group type controller did not validate a CSRF token on its delete action, allowing for cross-site request forgery. An authenticated user with group type management permission could be tricked into deleting a custom group type by a remote unauthenticated attacker.
A stored XSS vulnerability exists in Concrete CMS versions below 9.5.3, specifically in the Address attribute's country-less text formatter. This allows a user who can submit an Address attribute to execute script in the session of any dashboard user who opened the affected entry. The vulnerability was introduced due to a lack of HTML-escaping in the text formatter, which enabled the execution of maliciou [truncated]
A Cross-Site Scripting (XSS) vulnerability exists in Concrete CMS versions 9.0 to 9.5.2. An attacker who can create or rename pages could store a script through a child page name, which would execute in the browser of any visitor, editor, or administrator who views the navigation and opens the affected dropdown. The script executes with the victim's privileges, potentially allowing the attacker to read sa [truncated]
A vulnerability in Concrete CMS versions below 9.5.3 allows a remote attacker to inject persistent JavaScript into an existing Express form Text control, resulting in stored cross-site scripting. This occurs because the save_control action in the Express entities forms dashboard controller does not validate the anti-CSRF token, enabling an attacker to forge a cross-site request. The injected markup execut [truncated]
A stored cross-site scripting vulnerability exists in Concrete CMS versions prior to 9.5.3. An authenticated editor with high privileges could inject malicious HTML or script into form labels, which would then be executed in the browser of any administrator viewing the form submissions report. This issue was reported by Yonatan Drori from Tenzai and has been assigned a CVSS v4.0 score of 8.4.
An executive overview of CVE-2026-81895: Concrete CMS versions before 9.5.3 have a high-severity vulnerability allowing for stored, time-based blind SQL injection via the Document Library block. This issue arises from improper validation of file-set identifiers, which are concatenated directly into the file-set filter query without casting or binding as parameters. The vulnerability, scored 8.5 under CVSS [truncated]
A stored DOM-based Cross-site Scripting (XSS) vulnerability exists in Concrete CMS 9.5.2 and below via the Gallery block's per-image Caption field. This issue allows a user with permission to edit a page containing a Gallery block to store a caption that executes in the browser of any visitor who opens that image's lightbox. The vulnerability is due to the bundled Magnific Popup lightbox script re-parsing [truncated]
A stored cross-site scripting (XSS) vulnerability exists in Concrete CMS versions before 9.5.3 and 8.5.21. An authenticated user with page-editing permissions could inject arbitrary JavaScript, potentially leading to session hijacking and privilege escalation. The vulnerability allows an attacker to store a crafted external link value that breaks out of the link markup and injects arbitrary JavaScript, wh [truncated]
CVE-2026-18110 is a high-severity vulnerability in Concrete CMS versions 9.0.0 through 9.5.2. An unauthenticated attacker can exploit the user selector autocomplete endpoint to enumerate backend accounts, disclosing internal user IDs, usernames, and email addresses of administrative users. This vulnerability allows attackers to gather sensitive information without needing authentication, posing a signific [truncated]
A stored cross-site scripting (XSS) vulnerability exists in Concrete CMS versions 8.3.0 to 9.5.2. A registered user with permission to add events to a calendar governed by an approval workflow can submit an event with a script payload. When an administrator views the pending request in the dashboard 'Waiting For Me' block, the script executes. This could be used to create a new administrator account.