concretecms-community-store has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 8.1 (high).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Products
- community_store 1
- concretecms-community-store/community_store 1
Worst active — by depth score
CVE-2026-93659High· 8.7Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views60CVE-2026-95653High· 7.5Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead of random values, making tokens predictable41
concretecms-community-store vulnerabilities
CVEs affecting concretecms-community-store, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-95653High· 7.5Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead of random values, making tokens predictable
Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead of random values, making tokens predictable. Unauthenticated attackers can enumerate sequential order and file ident…
CVE-2026-93659High· 8.7PoCConcrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views
Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute …