CVE-2026-7890LOWCVSS 0.0

Concrete CMS's RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation

Published May 22, 2026·Updated Jun 24, 2026

Description

In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation enabling redirect-to-internal bypasses.

Affected Packages (1)

concrete5/concrete5COMPOSER
Fixed in 9.5.1

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free