EIP-2026-106122
PRE-CVEConcrete CMS < 5.5.21 - Multiple Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106122. PoCs published by AkaStep.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in Concrete CMS versions 5.5 and 5.5.21, including XSS, arbitrary file upload, and DoS. It provides URLs for XSS exploitation, details for shell upload via Flash uploader, and a Perl script for DoS attacks.
Description
Concrete CMS < 5.5.21 - Multiple Vulnerabilities
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by AkaStep · perlwebappsphp
https://www.exploit-db.com/exploits/37225
This exploit demonstrates multiple vulnerabilities in Concrete CMS versions 5.5 and 5.5.21, including XSS, arbitrary file upload, and DoS. It provides URLs for XSS exploitation, details for shell upload via Flash uploader, and a Perl script for DoS attacks.
Classification
Working Poc 90%
Attack Type
Xss | Dos | Other
Complexity
Trivial
Reliability
Reliable
Target:
Concrete CMS 5.5, 5.5.21
No auth needed
Prerequisites:
Access to the target Concrete CMS instance
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026