Skip to content

Known CVE

Concrete CMS <= 9.5.0 - Unauthenticated Conversation Message Disclosure (IDOR)

Concrete CMS <= 9.5.0 contains an IDOR caused by insufficient access control in /ccm/frontend/conversations/message_detail endpoint, letting unauthenticated attackers enumerate conversation messages and attachments.

CVE-2026-8237

Medium2026CVSS 5.3CWE-862

cve2026 · concretecms · concrete5 · idor · exposure

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website