Known CVE
Concrete CMS <9.5.1 - Unauthenticated File-Usage Internal Metadata Disclosure
Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate. The endpoint /ccm/system/dialogs/file/usage/{fID} accepts an integer file ID in the URL and returns internal site structure data (page IDs, versions, URL paths) to anyone who sends a GET request.
CVE-2026-8236
Medium2026CVSS 5.3CWE-862
cve2026 · concretecms · concrete5 · cms · unauth · exposure
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website