PatchSiren

concretecms-community-store CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH concretecms-community-store CVE published 2026-09-22

CVE-2026-95653

CVE-2026-95653 debrief based on the supplied source corpus. Concrete CMS Community Store before 2.7.8 has a vulnerability in digital product download token generation, making tokens predictable. This allows unauthenticated attackers to calculate valid download tokens and retrieve digital goods purchased by other customers. Defenders and administrators should assess exposure and upgrade to version 2.7.8 or [truncated]