EIP-2026-106122

PRE-CVE

Concrete CMS < 5.5.21 - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-106122. PoCs published by AkaStep.

AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in Concrete CMS versions 5.5 and 5.5.21, including XSS, arbitrary file upload, and DoS. It provides URLs for XSS exploitation, details for shell upload via Flash uploader, and a Perl script for DoS attacks.

Description

Concrete CMS < 5.5.21 - Multiple Vulnerabilities

Exploits (1)

exploitdb WORKING POC VERIFIED
by AkaStep · perlwebappsphp
https://www.exploit-db.com/exploits/37225

This exploit demonstrates multiple vulnerabilities in Concrete CMS versions 5.5 and 5.5.21, including XSS, arbitrary file upload, and DoS. It provides URLs for XSS exploitation, details for shell upload via Flash uploader, and a Perl script for DoS attacks.

Classification
Working Poc 90%
Attack Type
Xss | Dos | Other
Complexity
Trivial
Reliability
Reliable
Target: Concrete CMS 5.5, 5.5.21
No auth needed
Prerequisites: Access to the target Concrete CMS instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026