Server-Side Template Injection in Concrete CMS by Concrete5
CVE-2026-81910
5.9MEDIUM
What is CVE-2026-81910?
Concrete CMS versions 9 through 9.5.2 are subject to a Server-Side Template Injection vulnerability that arises from unvalidated style values allowed in the Theme Customizer. Attackers can manipulate style properties, such as color channels, leading to the execution of arbitrary LESS directives. This could expose sensitive information, including database credentials and private keys, through the application’s public CSS cache. Intruders can potentially access internal network resources via PHP stream wrappers, raising significant security concerns for affected installations.
Affected Version(s)
Concrete CMS 9.0.0 <= 9.5.2
