Feed/CVE-2026-8237
CVE-2026-8237MEDIUMCVSS 5.3

Concrete CMS is vulnerable to IDOR

Published May 22, 2026·Updated Jul 23, 2026

NVD Description

Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations/message_detail` endpoint returns the full content of any conversation message. An unauthenticated attacker can enumerate all conversation messages, including messages from restricted pages, member-only areas, and the moderation queue. File attachments with download URLs are also exposed.

Affected Packages (1)

concrete5/concrete5COMPOSER
Fixed in 9.5.1

Public Exploits & PoCs1 found

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free