Server-side URL Fetch Vulnerability in Concrete CMS by Concrete5
CVE-2026-7890

2.1LOW

Key Information:

Vendor
CVE Published:
21 May 2026

What is CVE-2026-7890?

In versions 9.5.0 and lower of Concrete CMS, the RSS Displayer block fails to validate feed URLs provided by page editors before fetching them server-side. This flaw can lead to redirection to internal resources, exposing sensitive information and allowing unintended access within the internal network. The vulnerability highlights the need for stringent input validation to prevent unauthorized URL requests and potential data leaks.

Affected Version(s)

Concrete CMS 5.0 <= 9.5.0

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.