Path Traversal Vulnerability in Concrete CMS by Concrete5
CVE-2026-8134
9.4CRITICAL
What is CVE-2026-8134?
Concrete CMS versions 9.5.0 and earlier are susceptible to a path traversal vulnerability due to improper sanitization of user input in the ptComposerFormLayoutSetControlCustomTemplate field. This flaw allows an authenticated user with editing rights to exploit the system by including arbitrary files, potentially leading to remote code execution. The risk is exacerbated by the file uploader’s insufficient validation, which may allow malicious PHP code to be uploaded with common image file extensions, like .png.
Affected Version(s)
Concrete CMS 5.0 <= 9.5.0
