CVE-2026-10721
Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and Search components. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious serialized payload has been placed in the database. Thanks XananasX7 for reporting.
- Affected products
- Concrete Cms
- Fix
- Available
- CVSS 4.0
- 8.4 HIGH
- EPSS
- 0.1% (4th percentile)
- Weakness
- CWE-502
- NVD status
- Deferred
- Published
- 2026-06-10
- Attack patterns
- CAPEC-586
CVE-2026-10721 at NVD
No indexed exploits for CVE-2026-10721 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-10721 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.