PHP Object Injection Vulnerability in Concrete CMS by Concrete5
CVE-2026-10721
8.4HIGH
What is CVE-2026-10721?
Concrete CMS versions prior to 9.5.2 have a vulnerability that allows for PHP Object Injection through the unserialize() function in the Permission, Cache, and Search components. An unauthenticated attacker can exploit this flaw by injecting a malicious serialized payload into the database, enabling arbitrary PHP object instantiation. This vulnerability poses serious security risks that could be leveraged to execute unauthorized actions within the CMS.
Affected Version(s)
Concrete CMS 5 <= 9.5.1
