CVE-2026-95653

Source
https://cve.org/CVERecord?id=CVE-2026-95653
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-95653.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-95653
Published
2026-09-22T15:24:11Z
Modified
2026-09-24T03:46:47Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Concrete CMS Community Store before 2.7.8 Predictable Digital Download Token
Details

Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead of random values, making tokens predictable. Unauthenticated attackers can enumerate sequential order and file identifiers to calculate valid download tokens and retrieve digital goods purchased by other customers.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-340"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/95xxx/CVE-2026-95653.json"
}
References

Affected packages

Git / github.com/concretecms-community-store/community_store

Affected ranges

Type
GIT
Repo
https://github.com/concretecms-community-store/community_store
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "2.7.8"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

v.*
v.2.4.4
v1.*
v1.0.1
v1.0.7
v1.0.8
v1.1.3
v1.1.4
v1.1.5
v1.2
v1.2.1
v1.2.3
v1.3
v1.3.1
v1.3.2
v1.3.4
v1.3.6
v1.4.2
v2.*
v2.0.4
v2.1.10
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.1.7
v2.1.9
v2.2.1
v2.2.2
v2.2.5
v2.2.6
v2.2.7
v2.3
v2.3.1
v2.3.4
v2.3.6
v2.4.3
v2.4.6
v2.4.7.1
v2.4.7.2
v2.4.7.3
v2.4.7.4
v2.4.7.5
v2.4.7.6
v2.4.7.7
v2.4.7.8
v2.4.8.2
v2.4.8.4
v2.4.8.5
v2.5
v2.5.1
v2.6
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.6.5
v2.7
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.6
v2.7.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-95653.json"