Junglewise Threat Intelligence

CVE-2026-7890: Concrete CMS SSRF in RSS Displayer block

CVE-2026-7890 · Severity: medium · CVSS 4 · Published 2026-05-21

Technologies: Concrete CMS, concrete5/concrete5 (Packagist). Vendors: Concrete CMS, Packagist.

Executive brief

Concrete CMS, a platform used for building and managing websites, contains a vulnerability in its RSS Displayer component. An authorized page editor can provide a malicious web address that the server will then attempt to visit. This could allow an attacker to bypass internal security redirects or probe internal network resources that are not normally accessible from the internet.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Concrete CMS versions 9.5.0 and below within the RSS Displayer block. The component accepts a user-provided feed URL from any page editor and fetches the content server-side without sufficient validation. This flaw enables 'redirect-to-internal' bypasses, allowing an attacker with high privileges (page editor) to force the server to make requests to internal or restricted network locations. The issue is addressed in version 9.5.1 by implementing new URL validation utilities.

Affected products

  • Concrete CMS Concrete CMS <= 9.5.0

Timeline

  • 2026-05-21: disclosed: NVD Published Date
  • 2026-05-22: advisory: GitHub Advisory published
  • 2026-06-24: patched: GitHub Advisory reviewed and updated with patch info

References

Related threats