CVE-2026-95653
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
22/09/2026
Last modified:
22/09/2026
Description
Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead of random values, making tokens predictable. Unauthenticated attackers can enumerate sequential order and file identifiers to calculate valid download tokens and retrieve digital goods purchased by other customers.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/concretecms-community-store/community_store
- https://github.com/concretecms-community-store/community_store/blob/v2.7.7/src/CommunityStore/Utilities/Download.php#L17
- https://github.com/concretecms-community-store/community_store/blob/v2.7.7/src/CommunityStore/Utilities/Download.php#L45
- https://github.com/concretecms-community-store/community_store/commit/a71138db250d5c207e49fe3f1287241f04e3f747
- https://github.com/concretecms-community-store/community_store/releases/tag/v2.7.8
- https://www.vulncheck.com/advisories/concrete-cms-community-store-before-2.7.8-predictable-digital-download-token


