CVE-2026-68531
Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard characters in the keyword search filters used by the file manager, file folders, and page list, allowing an authenticated user with editor-level or higher privileges to submit a crafted search containing many single-character wildcards. Because the keyword input was placed into the LIKE clause without neutralizing its wildcard metacharacters, a short request could force the database to evaluate every row and perform a full-table scan, and repeated or wildcard-dense searches could sustain elevated database CPU and I/O, degrading responsiveness for other users on large installations. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N. Thanks noivan for reporting.
Scoring
- Severity
- LOW
- CVSS base score
- 2.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.25%
- CWE
- CWE-405
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- Concrete CMS Concrete CMS
Weakness type
Related vulnerabilities
- CVE-2026-54874 — Excessive Memory Use Buffering DTLS Records for a Future Epoch
- CVE-2026-25611 — Pre-Authentication Memory Exhaustion Denial of Service in MongoDB Server
- CVE-2025-53633 — Chall-Manager's scenario decoding process does not check for zip bombs
- CVE-2024-56200 — Uncontrolled Recursion and Asymmetric Resource Consumption in Altair media/file proxy
- CVE-2021-38447 — OCI OpenDDS Secure Amplification
- CVE-2025-42874 — Denial of service (DOS) in SAP NetWeaver (remote service for Xcelsius)
- CVE-2024-11187 — Many records in the additional section cause CPU exhaustion
- CVE-2024-45590 — body-parser vulnerable to denial of service when url encoding is enabled