Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2026-8411

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete_CVE-2026-8411

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete. The Concrete CMS se...

Concrete CMS Concrete CMS 9.0 CVE
LOW 2.3 CVE-2026-8410

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete_CVE-2026-8410

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete.  The The Concrete C...

Concrete CMS Concrete CMS 9.0 CVE
LOW 2.3 CVE-2026-7887

For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status_CVE-2026-7887

For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status. A user with uIsActive=0 (suspended, banned, termina...

Concrete CMS Concrete CMS 5.0 CVE
LOW 2.3 CVE-2026-7886

Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter_CVE-2026-7886

Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter which can lead to file permission bypass...

Concrete CMS Concrete CMS 5.0 CVE
LOW 2.3 CVE-2026-7882

Concrete CMS 9.5.0 and below is vulnerable to CSRF via the DeleteFile controller_CVE-2026-7882

Concrete CMS 9.5.0 and below is vulnerable to unauthorized file deletion due to an Inverted CSRF token check in the DeleteFile controller. The cod...

Concrete CMS Concrete CMS 5.0 CVE
LOW 2.3 CVE-2026-8409

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete_CVE-2026-8409

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete.  The The Concrete CMS se...

Concrete CMS Concrete CMS 9.0 CVE
LOW 2 CVE-2026-8139

Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName_CVE-2026-8139

Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updateCollectionAliasExternal bypasses being sanitiz...

Concrete CMS Concrete CMS 5.0 CVE
LOW 2.1 CVE-2026-7890

Concrete CMS 9.5.0 is vulnerable to SSRF via RSS Displayer Block_CVE-2026-7890

In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation enab...

Concrete CMS Concrete CMS 5.0 CVE
LOW 3.7 CVE-2026-7837

TOCTOU with root privilege in ad_flush_CVE-2026-7837

A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through 4.4.2 involves root-privileged file operations, w...

Netatalk Netatalk 3.0.0 CVE
LOW 3.7 CVE-2026-44075

Missing break in DSI OpenSession_CVE-2026-44075

A missing break statement in DSI OpenSession processing in Netatalk 1.5.0 through 4.4.2 causes a DSIOPT_ATTNQUANT switch case to fall through into ...

Netatalk Netatalk 1.5.0 CVE