CVE-2026-81895 | Concrete CMS up to 9.5.2 Document Library block btDocumentLibrary.setIds fsID sql injection
A vulnerability was found in Concrete CMS up to 9.5.2 and classified as problematic. The affected element is the function btDocumentLibrary.setIds of the component Document Library block. Such manipulation of the argument fsID leads to sql injection.
This vulnerability is documented as CVE-2026-81895. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More