PT-2026-91564 · Unknown · Concrete Cms

·

CVE-2026-81902

·

Published

2026-09-14

·

Updated

2026-09-19

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Concrete CMS versions 9 through 9.5.2
Description Concrete CMS fails to validate a Cross-Site Request Forgery (CSRF) token—a unique value used to verify that a request was intentionally sent by the user—in the removeOrphanedBlocks action within the orphaned block removal panel. A remote attacker can craft a request that, if loaded by an authenticated user with edit permissions on a target page, deletes all blocks on the current version of that page. Blocks not aliased to another page or scrapbook entry are permanently removed from the global Blocks table and their block-type data table, resulting in permanent content destruction.
Recommendations Update Concrete CMS to version 9.5.3 or later.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81902

Affected Products

Concrete Cms