HIGH
concretecms-community-store
CVE published 2026-09-22
CVE-2026-95653
CVE-2026-95653 debrief based on the supplied source corpus. Concrete CMS Community Store before 2.7.8 has a vulnerability in digital product download token generation, making tokens predictable. This allows unauthenticated attackers to calculate valid download tokens and retrieve digital goods purchased by other customers. Defenders and administrators should assess exposure and upgrade to version 2.7.8 or [truncated]