Server-side URL Fetch Vulnerability in Concrete CMS by Concrete5
CVE-2026-7890
2.1LOW
What is CVE-2026-7890?
In versions 9.5.0 and lower of Concrete CMS, the RSS Displayer block fails to validate feed URLs provided by page editors before fetching them server-side. This flaw can lead to redirection to internal resources, exposing sensitive information and allowing unintended access within the internal network. The vulnerability highlights the need for stringent input validation to prevent unauthorized URL requests and potential data leaks.
Affected Version(s)
Concrete CMS 5.0 <= 9.5.0
