GHSA-52pr-7vmf-2w7xHigh

Concrete CMS is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components

Published
June 3, 2026
Last Modified
July 14, 2026

🔗 CVE IDs covered (1)

📋 Description

Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious serialized payload has been placed in the database. The Concrete CMS security team thanks XananasX7 and Sanjorn Keeratirungsan (dizconnect) for both independently reporting this ssue.

🎯 Affected products1

  • composer/concrete5/concrete5:< 9.5.2

🔗 References (4)