Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and Search components
CVE-2026-10721
8.4HIGH
What is CVE-2026-10721?
Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection viaĀ unserialize()Ā calls in theĀ Ā in Permission, Cache, and SearchĀ components. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious serialized payload has been placed in the database. Thanks XananasX7 forĀ reporting.
Affected Version(s)
Concrete CMS 5 <= 9.5.1
