Concrete5 CMS version 9.1.3 contains an XPath injection vulnerability that allows attackers to manipulate URL path parameters with malicious payloads. Attackers can flood the system with crafted requests to potentially extract internal content paths and system information.
Metrics
Affected Vendors & Products
References
History
Wed, 14 Jan 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Portlandlabs
Portlandlabs concrete Cms |
|
| Vendors & Products |
Portlandlabs
Portlandlabs concrete Cms |
Tue, 13 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Concrete5 CMS version 9.1.3 contains an XPath injection vulnerability that allows attackers to manipulate URL path parameters with malicious payloads. Attackers can flood the system with crafted requests to potentially extract internal content paths and system information. | |
| Title | Concrete5 CME 9.1.3 - Xpath injection | |
| Weaknesses | CWE-643 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-01-13T22:51:40.976Z
Updated: 2026-01-13T22:51:40.976Z
Reserved: 2025-12-27T13:53:29.756Z
Link: CVE-2022-50807
No data.
Status : Received
Published: 2026-01-13T23:15:50.003
Modified: 2026-01-13T23:15:50.003
Link: CVE-2022-50807
No data.