Feed/CVE-2026-10721
CVE-2026-10721HIGHCVSS 0.0

CVE-2026-10721

Published Jun 10, 2026·Updated Aug 12, 2026

NVD Description

Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the  in Permission, Cache, and Search components. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious serialized payload has been placed in the database. Thanks XananasX7 for reporting.

Affected Packages (1)

concrete5/concrete5COMPOSER
Fixed in 9.5.2

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free