PT-2026-96817 · Concrete Cms · Concrete Cms Community Store

CVE-2026-95653

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Concrete CMS Community Store versions prior to 2.7.8
Description Digital product download tokens are derived from order creation timestamps rather than random values, which makes the tokens predictable. Unauthenticated attackers can enumerate sequential order and file identifiers to calculate valid download tokens and retrieve digital goods purchased by other customers.
Recommendations Update Concrete CMS Community Store to version 2.7.8 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-95653

Affected Products

Concrete Cms Community Store