Description
Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page. The reset() controller action cleared the administrator-configured reserved-word list (concrete.seo.exclude_words) but did not validate the anti-CSRF token that the reset modal emitted, and it did not restrict the request to the POST method. A remote attacker who lured an authenticated user with SEO access to a crafted page could revert the reserved-word list to its default and silently alter future URL-slug generation for pages, files, topics, and other objects created through the Text urlify service, undoing the site's configured SEO slug policy. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.
Published: 2026-09-15
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unintended configuration change via CSRF
Action: Upgrade CMS
AI Analysis

Impact

Concrete CMS versions before 9.5.3 contain a Cross‑Site Request Forgery flaw in the Dashboard SEO Excluded Words Reset endpoint. The reset action clears the admin‑configured list of reserved words without validating the anti‑CSRF token or limiting the request to the POST method, as described by the CWEs. An attacker who lures an authenticated user with SEO privileges to a crafted page can force the site to restore the default excluded word list, silently modifying how URL slugs are generated for pages, files, topics, and other objects. This change undermines the site’s SEO policy and can cause broken URLs or degraded search engine rankings. The abuse does not disclose or modify data directly, but it alters critical site configuration.

Affected Systems

Affected systems include all installations of Concrete CMS running a version earlier than 9.5.3. The vulnerability is present on the dashboard under the SEO management section and requires the target user to have administrative access to the SEO module. Vendor descriptions state the fix is applied in version 9.5.3 and later.

Risk and Exploitability

The risk is low in terms of confidentiality, integrity, and availability as the CVSS v4.0 score is 2.3 and the EPSS score is below 1%. The flaw requires an attacker to trick an authenticated user, which limits the exposure to sites with many authenticated administrators or those with broad SEO access. The flaw is not listed in the CISA KEV catalog, and there are no known public exploits as of the latest data. Nevertheless, a CSRF attack can still disrupt search engine optimization, so remediation is advisable.

Generated by OpenCVE AI on September 20, 2026 at 13:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Concrete CMS 9.5.3 or later patch to eliminate the CSRF vulnerability in the SEO Excluded Words Reset endpoint
  • If immediate upgrade is not possible, restrict access to the SEO controls so only a minimal trusted group can invoke the reset function
  • Implement a WAF or equivalent rule to drop any request to the reset endpoint that does not use a POST method or that lacks a valid CSRF token

Generated by OpenCVE AI on September 20, 2026 at 13:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Tue, 15 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page. The reset() controller action cleared the administrator-configured reserved-word list (concrete.seo.exclude_words) but did not validate the anti-CSRF token that the reset modal emitted, and it did not restrict the request to the POST method. A remote attacker who lured an authenticated user with SEO access to a crafted page could revert the reserved-word list to its default and silently alter future URL-slug generation for pages, files, topics, and other objects created through the Text urlify service, undoing the site's configured SEO slug policy. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.
Title Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Dashboard SEO Excluded Words Reset Endpoint
Weaknesses CWE-352
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-15T19:40:58.435Z

Reserved: 2026-08-27T18:23:01.366Z

Link: CVE-2026-81920

cve-icon Vulnrichment

Updated: 2026-09-15T19:40:53.763Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:41.350

Modified: 2026-09-18T15:27:27.317

Link: CVE-2026-81920

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T13:15:14Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)