---
id: CVE-2026-95653
title: >-
  Concrete CMS Community Store before 2.7.8 derives digital product download
  tokens from order creation timestamps instead of random values, making tokens
  predictable
summary: >-
  Concrete CMS Community Store before 2.7.8 derives digital product download
  tokens from order creation timestamps instead of random values, making tokens
  predictable. Unauthenticated attackers can enumerate sequential order and file
  ident…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-340
vendor: concretecms-community-store
product: community_store
affected:
  - community_store < 2.7.8
published: '2026-09-22'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:55:25.800'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-95653'
references:
  - url: 'https://github.com/concretecms-community-store/community_store'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/concretecms-community-store/community_store/blob/v2.7.7/src/CommunityStore/Utilities/Download.php#L17
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/concretecms-community-store/community_store/blob/v2.7.7/src/CommunityStore/Utilities/Download.php#L45
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/concretecms-community-store/community_store/commit/a71138db250d5c207e49fe3f1287241f04e3f747
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/concretecms-community-store/community_store/releases/tag/v2.7.8
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/concrete-cms-community-store-before-2.7.8-predictable-digital-download-token
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-22T16:06:00.493Z'
epss: 0.00569
epssPercentile: 0.45917
---

## Overview

Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead of random values, making tokens predictable. Unauthenticated attackers can enumerate sequential order and file identifiers to calculate valid download tokens and retrieve digital goods purchased by other customers.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
