Server-Side Template Injection in Concrete CMS by Concrete5
CVE-2026-81910

5.9MEDIUM

Key Information:

Vendor
CVE Published:
11 September 2026

What is CVE-2026-81910?

Concrete CMS versions 9 through 9.5.2 are subject to a Server-Side Template Injection vulnerability that arises from unvalidated style values allowed in the Theme Customizer. Attackers can manipulate style properties, such as color channels, leading to the execution of arbitrary LESS directives. This could expose sensitive information, including database credentials and private keys, through the application’s public CSS cache. Intruders can potentially access internal network resources via PHP stream wrappers, raising significant security concerns for affected installations.

Affected Version(s)

Concrete CMS 9.0.0 <= 9.5.2

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tenzai
.