CVE-2026-95653
HIGHDescription
Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead of random values, making tokens predictable. Unauthenticated attackers can enumerate sequential order and file identifiers to calculate valid download tokens and retrieve digital goods purchased by other customers.
Is your site exposed to CVE-2026-95653?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
References
Other References
Frequently Asked Questions
What is CVE-2026-95653? +
How severe is CVE-2026-95653? +
How do I check if I'm vulnerable to CVE-2026-95653? +
Related Vulnerabilities
The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a …
ATutor generates predictable email confirmation tokens due to the use of insufficiently random values in the account confirmation functionality. Due …
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation …
The devices are vulnerable to session hijacking due to insufficient entropy in its session ID generation algorithm. The session IDs …
Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure. Apache::Session::Generate::ModUniqueId (added in version 1.54) uses the value …
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated using …