Cross-Site Request Forgery in Concrete CMS Dashboard by Concrete
CVE-2026-81920
2.3LOW
What is CVE-2026-81920?
Concrete CMS versions prior to 9.5.3 are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability impacting the dashboard's SEO Excluded Words functionality. The reset() controller action allows an attacker to manipulate the reserved-word list without proper anti-CSRF token validation or restrictions on request methods. By enticing an authenticated user with SEO privileges to a malicious page, an attacker could reset the reserved-word list, thereby undermining the intended SEO slug configurations for various digital content hosted through the Text urlify service.
Affected Version(s)
Concrete CMS 5.0.0 <= 9.5.2
