CVE-2026-18425
CVE-2026-18425 is a low-severity vulnerability in Concretecms Concrete Cms with a CVSS 3.x base score of 2.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-352.
Key facts
- Severity: Low (CVSS 3.x base score 2.7)
- CVSS v4: 2.1
- EPSS exploit prediction: 0% (2nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-352
- Affected product: Concretecms Concrete Cms
- Published:
- Last modified:
Description
Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap reorder action (Concrete\Controller\Backend\Dashboard\SitemapUpdate) using only the global access_sitemap task permission and did not check per-page edit permission before updating each page's display order. As a result, an authenticated user granted sitemap access could change the display order (cDisplayOrder) of any pages they had no rights to edit, altering the order in which those pages render in navigation, breadcrumb, and page-list output. The reorder action additionally validated no CSRF token, so the write could be triggered by a forged request. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
Frequently asked questions
- What is CVE-2026-18425?
- Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap reorder action (Concrete\Controller\Backend\Dashboard\SitemapUpdate) using only the global access_sitemap task permission and did not check per-page edit permission before updating each page's display order. As a result, an authenticated user granted sitemap access could change the display order (cDisplayOrder) of any pages they had no rights to edit, altering the order in which those pages render in navigation, breadcrumb, and page-list output. The reorder action additionally validated no CSRF token, so the write could be triggered by a forged request. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
- How severe is CVE-2026-18425?
- CVE-2026-18425 has a CVSS 3.x base score of 2.7, rated low severity. It is exploitable over network with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability none.
- Is CVE-2026-18425 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (2nd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-18425?
- CVE-2026-18425 affects Concretecms Concrete Cms. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-18425?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-18425 published?
- CVE-2026-18425 was published on 2026-09-15 and last updated on 2026-09-21.
References
Affected products (1)
- cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
More vulnerabilities in Concretecms Concrete Cms
- CVE-2023-48648 — Critical (CVSS 9.8): Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with…
- CVE-2022-21829 — Critical (CVSS 9.8): Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from…
- CVE-2021-22958 — Critical (CVSS 9.8): A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP…
- CVE-2021-40098 — Critical (CVSS 9.8): An issue was discovered in Concrete CMS through 8.5.5. Path Traversal leading to RCE via external form by adding a…
- CVE-2026-85385 — Critical (CVSS 9.6): Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output…
- CVE-2022-30117 — Critical (CVSS 9.1): Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 allow traversal in /index.php/ccm/system/file/upload…
All CVEs affecting Concretecms Concrete Cms →
Other CWE-352 (Cross-Site Request Forgery (CSRF)) vulnerabilities
- CVE-2025-15399 — Critical (CVSS 10.0): IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to…
- CVE-2025-32642 — Critical (CVSS 10.0): Cross-Site Request Forgery (CSRF) vulnerability in appsbd Vite Coupon vite-coupon allows Remote Code Inclusion.This…
- CVE-2025-23922 — Critical (CVSS 10.0): Cross-Site Request Forgery (CSRF) vulnerability in Harsh iSpring Embedder embed-ispring allows Upload a Web Shell to a…
- CVE-2017-5145 — Critical (CVSS 10.0): An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware…
- CVE-2019-25729 — Critical (CVSS 9.8): PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute…
- CVE-2025-48340 — Critical (CVSS 9.8): Cross-Site Request Forgery (CSRF) vulnerability in Danny Vink User Profile Meta Manager user-profile-meta allows…
Browse all CWE-352 (Cross-Site Request Forgery (CSRF)) vulnerabilities →