VYPR

Community Store

by Concrete CMS

CVEs (1)

  • CVE-2026-93659HigSep 18, 2026
    risk 0.50cvss 8.7epss

    Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to…