Skip to content

Known CVE

Concrete CMS <9.5.1 - Unauthenticated File Usage Disclosure

Concrete CMS 9.5.0 and below is vulnerable to unauthenticated file usage disclosure via missing permission check in the usage controller.

CVE-2026-6826

Medium2026CVSS 6.9CWE-862

cve2026 · concretecms · concrete · disclosure · unauth · idor

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website