CVE-2026-10721

Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the  in Permission, Cache, and Search components. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious serialized payload has been placed in the database. Thanks XananasX7 for reporting.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-06-10 08:16

Updated : 2026-07-23 09:10


NVD link : CVE-2026-10721

Mitre link : CVE-2026-10721

CVE.ORG link : CVE-2026-10721


JSON object : View

Products Affected

No product.

CWE
CWE-502

Deserialization of Untrusted Data