GHSA-46xh-7854-f568MediumCVSS 5.3

Concrete CMS is vulnerable to authorization bypass in the Calendar Block

Published
May 21, 2026
Last Modified
June 24, 2026

🔗 CVE IDs covered (1)

📋 Description

Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calendar Block since action_get_events does not check canView on the calendar which results in restricted event details being disclosed.

🎯 Affected products1

  • composer/concrete5/concrete5:< 9.5.1

🔗 References (3)