PT-2026-96817 · Concrete Cms · Concrete Cms Community Store
CVE-2026-95653
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Concrete CMS Community Store versions prior to 2.7.8
Description
Digital product download tokens are derived from order creation timestamps rather than random values, which makes the tokens predictable. Unauthenticated attackers can enumerate sequential order and file identifiers to calculate valid download tokens and retrieve digital goods purchased by other customers.
Recommendations
Update Concrete CMS Community Store to version 2.7.8 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Concrete Cms Community Store