Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gjwq-9v8p-47w7 | Concrete CMS's RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation |
Tue, 26 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Fri, 22 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 21 May 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Concretecms
Concretecms concrete Cms |
|
| Vendors & Products |
Concretecms
Concretecms concrete Cms |
Thu, 21 May 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation enabling redirect-to-internal bypasses. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.1 with a vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N. | |
| Title | Concrete CMS 9.5.0 is vulnerable to SSRF via RSS Displayer Block | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ConcreteCMS
Published:
Updated: 2026-05-22T12:54:45.612Z
Reserved: 2026-05-05T20:53:35.093Z
Link: CVE-2026-7890
Updated: 2026-05-22T12:54:41.747Z
Status : Analyzed
Published: 2026-05-21T22:16:49.400
Modified: 2026-06-17T11:03:04.800
Link: CVE-2026-7890
No data.
OpenCVE Enrichment
Updated: 2026-05-21T23:30:22Z
Github GHSA