🔐 CVE Alert

CVE-2026-2994

UNKNOWN 0.0

Concrete CMS below 9.4.8 is vulnerable to CSRF by a Rogue Admin using the Anti-Spam Allowlist Group

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configuration via group_id parameter which can leads to a security bypass since changes are saved prior to checking the CSRF token. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks z3rco for reporting

CWE CWE-352
Vendor concrete cms
Product concrete cms
Published Mar 4, 2026
Last Updated Mar 4, 2026
Stay Ahead of the Next One

Get instant alerts for concrete cms concrete cms

Be the first to know when new unknown vulnerabilities affecting concrete cms concrete cms are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Concrete CMS / Concrete CMS
All versions affected

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/concretecms/concretecms/pull/12826 documentation.concretecms.org: https://documentation.concretecms.org/9-x/developers/introduction/version-history/948-release-notes

Credits

🔍 z3rco