
CVE-2026-7890 In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation enabling redirect-to-inte… https://www.cve.org/CVERecord?id=CVE-2026-7890
Post summary
The post discloses CVE‑2026‑7890 affecting Concrete CMS 9.5.0 and earlier; the RSS Displayer block accepts arbitrary feed URLs and retrieves them server‑side without validation, potentially facilitating redirects or SSRF. No PoC, exploit, active exploitation, or patch information is provided.
