Cross-Site Request Forgery in Concrete CMS Dashboard by Concrete
CVE-2026-81920

2.3LOW

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-81920?

Concrete CMS versions prior to 9.5.3 are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability impacting the dashboard's SEO Excluded Words functionality. The reset() controller action allows an attacker to manipulate the reserved-word list without proper anti-CSRF token validation or restrictions on request methods. By enticing an authenticated user with SEO privileges to a malicious page, an attacker could reset the reserved-word list, thereby undermining the intended SEO slug configurations for various digital content hosted through the Text urlify service.

Affected Version(s)

Concrete CMS 5.0.0 <= 9.5.2

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

riodrwn
.