Skip to content

Known CVE

Concrete CMS <9.5.1 - Unauthenticated File-Usage Internal Metadata Disclosure

Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate. The endpoint /ccm/system/dialogs/file/usage/{fID} accepts an integer file ID in the URL and returns internal site structure data (page IDs, versions, URL paths) to anyone who sends a GET request.

CVE-2026-8236

Medium2026CVSS 5.3CWE-862

cve2026 · concretecms · concrete5 · cms · unauth · exposure

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website