{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-2994",
        "tracking": {
            "current_release_date": "2026-03-20T09:34:46.745557Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-2994",
            "initial_release_date": "2026-03-04T03:25:13.321584Z",
            "revision_history": [
                {
                    "date": "2026-03-04T03:25:13.321584Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-03-04T03:25:15.788898Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-04T03:38:36.262273Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1).| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-03-04T03:38:40.350005Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-04T07:35:10.064813Z",
                    "number": "5",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-04T15:15:46.919147Z",
                    "number": "6",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-04T15:15:53.992461Z",
                    "number": "7",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-04T15:39:21.447612Z",
                    "number": "8",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-04T21:51:03.645238Z",
                    "number": "9",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-03-04T21:51:07.196106Z",
                    "number": "10",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-04T22:25:16.925552Z",
                    "number": "11",
                    "summary": "CVSS created.| Products connected (1).| Product Identifiers created (1).| Exploits created (1)."
                },
                {
                    "date": "2026-03-04T22:25:20.451548Z",
                    "number": "12",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-05T00:31:45.553596Z",
                    "number": "13",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (86).| Product Identifiers created (85).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-05T00:31:56.345639Z",
                    "number": "14",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T09:34:42.854064Z",
                    "number": "15",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T09:34:45.334188Z",
                    "number": "16",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "16"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:git/5|<9.4.8",
                                "product": {
                                    "name": "vers:git/5|<9.4.8",
                                    "product_id": "CSAFPID-5757538"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<9.4.8",
                                "product": {
                                    "name": "vers:unknown/<9.4.8",
                                    "product_id": "CSAFPID-5759390",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Concrete CMS"
                    }
                ],
                "category": "vendor",
                "name": "Concrete CMS"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.0",
                                "product": {
                                    "name": "vers:unknown/8.0",
                                    "product_id": "CSAFPID-5759957",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.0.1",
                                "product": {
                                    "name": "vers:unknown/8.0.1",
                                    "product_id": "CSAFPID-5759958",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.0.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.0.2",
                                "product": {
                                    "name": "vers:unknown/8.0.2",
                                    "product_id": "CSAFPID-5759959",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.0.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.0.3",
                                "product": {
                                    "name": "vers:unknown/8.0.3",
                                    "product_id": "CSAFPID-5759960",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.0.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.1.0",
                                "product": {
                                    "name": "vers:unknown/8.1.0",
                                    "product_id": "CSAFPID-5759961",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.1.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.2.0",
                                "product": {
                                    "name": "vers:unknown/8.2.0",
                                    "product_id": "CSAFPID-5759962",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.2.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.2.0rc2",
                                "product": {
                                    "name": "vers:unknown/8.2.0rc2",
                                    "product_id": "CSAFPID-5759963",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.2.0RC2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.2.1",
                                "product": {
                                    "name": "vers:unknown/8.2.1",
                                    "product_id": "CSAFPID-5759964",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.2.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.3.0",
                                "product": {
                                    "name": "vers:unknown/8.3.0",
                                    "product_id": "CSAFPID-5759965",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.3.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.3.1",
                                "product": {
                                    "name": "vers:unknown/8.3.1",
                                    "product_id": "CSAFPID-5759966",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.3.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.3.2",
                                "product": {
                                    "name": "vers:unknown/8.3.2",
                                    "product_id": "CSAFPID-5759967",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.3.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.4.0",
                                "product": {
                                    "name": "vers:unknown/8.4.0",
                                    "product_id": "CSAFPID-5759968",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.4.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.4.0rc3",
                                "product": {
                                    "name": "vers:unknown/8.4.0rc3",
                                    "product_id": "CSAFPID-5759969",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.4.0RC3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.4.0rc4",
                                "product": {
                                    "name": "vers:unknown/8.4.0rc4",
                                    "product_id": "CSAFPID-5759970",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.4.0RC4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.4.1",
                                "product": {
                                    "name": "vers:unknown/8.4.1",
                                    "product_id": "CSAFPID-5759971",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.4.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.4.2",
                                "product": {
                                    "name": "vers:unknown/8.4.2",
                                    "product_id": "CSAFPID-5759972",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.4.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.4.3",
                                "product": {
                                    "name": "vers:unknown/8.4.3",
                                    "product_id": "CSAFPID-5759973",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.4.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.4.4",
                                "product": {
                                    "name": "vers:unknown/8.4.4",
                                    "product_id": "CSAFPID-5759974",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.4.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.4.5",
                                "product": {
                                    "name": "vers:unknown/8.4.5",
                                    "product_id": "CSAFPID-5759975",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.4.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.0",
                                "product": {
                                    "name": "vers:unknown/8.5.0",
                                    "product_id": "CSAFPID-5759976",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.0rc1",
                                "product": {
                                    "name": "vers:unknown/8.5.0rc1",
                                    "product_id": "CSAFPID-5759977",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.0RC1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.0rc2",
                                "product": {
                                    "name": "vers:unknown/8.5.0rc2",
                                    "product_id": "CSAFPID-5759978",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.0RC2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.1",
                                "product": {
                                    "name": "vers:unknown/8.5.1",
                                    "product_id": "CSAFPID-5759979",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.10",
                                "product": {
                                    "name": "vers:unknown/8.5.10",
                                    "product_id": "CSAFPID-5759980",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.10"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.11",
                                "product": {
                                    "name": "vers:unknown/8.5.11",
                                    "product_id": "CSAFPID-5759981",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.11"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.12",
                                "product": {
                                    "name": "vers:unknown/8.5.12",
                                    "product_id": "CSAFPID-5759982",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.12"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.13",
                                "product": {
                                    "name": "vers:unknown/8.5.13",
                                    "product_id": "CSAFPID-5759983",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.13"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.14",
                                "product": {
                                    "name": "vers:unknown/8.5.14",
                                    "product_id": "CSAFPID-5759984",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.14"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.15",
                                "product": {
                                    "name": "vers:unknown/8.5.15",
                                    "product_id": "CSAFPID-5759985",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.15"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.16",
                                "product": {
                                    "name": "vers:unknown/8.5.16",
                                    "product_id": "CSAFPID-5759986",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.16"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.17",
                                "product": {
                                    "name": "vers:unknown/8.5.17",
                                    "product_id": "CSAFPID-5759987",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.17"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.18",
                                "product": {
                                    "name": "vers:unknown/8.5.18",
                                    "product_id": "CSAFPID-5759988",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.18"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.19",
                                "product": {
                                    "name": "vers:unknown/8.5.19",
                                    "product_id": "CSAFPID-5759989",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.19"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.2",
                                "product": {
                                    "name": "vers:unknown/8.5.2",
                                    "product_id": "CSAFPID-5759990",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.20",
                                "product": {
                                    "name": "vers:unknown/8.5.20",
                                    "product_id": "CSAFPID-5759991",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.20"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.21",
                                "product": {
                                    "name": "vers:unknown/8.5.21",
                                    "product_id": "CSAFPID-5759992",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.21"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.3",
                                "product": {
                                    "name": "vers:unknown/8.5.3",
                                    "product_id": "CSAFPID-5759993",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.4",
                                "product": {
                                    "name": "vers:unknown/8.5.4",
                                    "product_id": "CSAFPID-5759994",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.5",
                                "product": {
                                    "name": "vers:unknown/8.5.5",
                                    "product_id": "CSAFPID-5759995",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.6",
                                "product": {
                                    "name": "vers:unknown/8.5.6",
                                    "product_id": "CSAFPID-5759996",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.6rc1",
                                "product": {
                                    "name": "vers:unknown/8.5.6rc1",
                                    "product_id": "CSAFPID-5759997",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.6RC1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.7",
                                "product": {
                                    "name": "vers:unknown/8.5.7",
                                    "product_id": "CSAFPID-5759998",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.8",
                                "product": {
                                    "name": "vers:unknown/8.5.8",
                                    "product_id": "CSAFPID-5759999",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.8"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.9",
                                "product": {
                                    "name": "vers:unknown/8.5.9",
                                    "product_id": "CSAFPID-5760000",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@8.5.9"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.0.0",
                                "product": {
                                    "name": "vers:unknown/9.0.0",
                                    "product_id": "CSAFPID-5760001",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.0.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.0.0rc1",
                                "product": {
                                    "name": "vers:unknown/9.0.0rc1",
                                    "product_id": "CSAFPID-5760002",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.0.0RC1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.0.0rc3",
                                "product": {
                                    "name": "vers:unknown/9.0.0rc3",
                                    "product_id": "CSAFPID-5760003",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.0.0RC3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.0.0rc4",
                                "product": {
                                    "name": "vers:unknown/9.0.0rc4",
                                    "product_id": "CSAFPID-5760004",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.0.0RC4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.0.1",
                                "product": {
                                    "name": "vers:unknown/9.0.1",
                                    "product_id": "CSAFPID-5760005",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.0.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.0.2",
                                "product": {
                                    "name": "vers:unknown/9.0.2",
                                    "product_id": "CSAFPID-5760006",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.0.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.1.0",
                                "product": {
                                    "name": "vers:unknown/9.1.0",
                                    "product_id": "CSAFPID-5760007",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.1.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.1.1",
                                "product": {
                                    "name": "vers:unknown/9.1.1",
                                    "product_id": "CSAFPID-5760008",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.1.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.1.2",
                                "product": {
                                    "name": "vers:unknown/9.1.2",
                                    "product_id": "CSAFPID-5760009",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.1.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.1.3",
                                "product": {
                                    "name": "vers:unknown/9.1.3",
                                    "product_id": "CSAFPID-5428999",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.1.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.2.0",
                                "product": {
                                    "name": "vers:unknown/9.2.0",
                                    "product_id": "CSAFPID-5760010",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.2.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.2.0rc2",
                                "product": {
                                    "name": "vers:unknown/9.2.0rc2",
                                    "product_id": "CSAFPID-5760011",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.2.0RC2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.2.1",
                                "product": {
                                    "name": "vers:unknown/9.2.1",
                                    "product_id": "CSAFPID-5760012",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.2.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.2.2",
                                "product": {
                                    "name": "vers:unknown/9.2.2",
                                    "product_id": "CSAFPID-5760013",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.2.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.2.3",
                                "product": {
                                    "name": "vers:unknown/9.2.3",
                                    "product_id": "CSAFPID-5760014",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.2.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.2.4",
                                "product": {
                                    "name": "vers:unknown/9.2.4",
                                    "product_id": "CSAFPID-5760015",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.2.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.2.5",
                                "product": {
                                    "name": "vers:unknown/9.2.5",
                                    "product_id": "CSAFPID-5760016",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.2.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.2.6",
                                "product": {
                                    "name": "vers:unknown/9.2.6",
                                    "product_id": "CSAFPID-5760017",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.2.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.2.7",
                                "product": {
                                    "name": "vers:unknown/9.2.7",
                                    "product_id": "CSAFPID-5760018",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.2.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.2.8",
                                "product": {
                                    "name": "vers:unknown/9.2.8",
                                    "product_id": "CSAFPID-5760019",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.2.8"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.2.9",
                                "product": {
                                    "name": "vers:unknown/9.2.9",
                                    "product_id": "CSAFPID-5760020",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.2.9"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.3.0",
                                "product": {
                                    "name": "vers:unknown/9.3.0",
                                    "product_id": "CSAFPID-5760021",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.3.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.3.1",
                                "product": {
                                    "name": "vers:unknown/9.3.1",
                                    "product_id": "CSAFPID-5760022",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.3.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.3.2",
                                "product": {
                                    "name": "vers:unknown/9.3.2",
                                    "product_id": "CSAFPID-5760023",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.3.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.3.3",
                                "product": {
                                    "name": "vers:unknown/9.3.3",
                                    "product_id": "CSAFPID-5760024",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.3.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.3.4",
                                "product": {
                                    "name": "vers:unknown/9.3.4",
                                    "product_id": "CSAFPID-5760025",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.3.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.3.5",
                                "product": {
                                    "name": "vers:unknown/9.3.5",
                                    "product_id": "CSAFPID-5760026",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.3.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.3.6",
                                "product": {
                                    "name": "vers:unknown/9.3.6",
                                    "product_id": "CSAFPID-5760027",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.3.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.3.7",
                                "product": {
                                    "name": "vers:unknown/9.3.7",
                                    "product_id": "CSAFPID-5760028",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.3.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.3.8",
                                "product": {
                                    "name": "vers:unknown/9.3.8",
                                    "product_id": "CSAFPID-5760029",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.3.8"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.3.9",
                                "product": {
                                    "name": "vers:unknown/9.3.9",
                                    "product_id": "CSAFPID-5760030",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.3.9"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.4.0",
                                "product": {
                                    "name": "vers:unknown/9.4.0",
                                    "product_id": "CSAFPID-5760031",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.4.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.4.0rc1",
                                "product": {
                                    "name": "vers:unknown/9.4.0rc1",
                                    "product_id": "CSAFPID-5760032",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.4.0RC1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.4.0rc2",
                                "product": {
                                    "name": "vers:unknown/9.4.0rc2",
                                    "product_id": "CSAFPID-5760033",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.4.0RC2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.4.1",
                                "product": {
                                    "name": "vers:unknown/9.4.1",
                                    "product_id": "CSAFPID-5760034",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.4.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.4.2",
                                "product": {
                                    "name": "vers:unknown/9.4.2",
                                    "product_id": "CSAFPID-5760035",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.4.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.4.3",
                                "product": {
                                    "name": "vers:unknown/9.4.3",
                                    "product_id": "CSAFPID-5760036",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.4.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.4.4",
                                "product": {
                                    "name": "vers:unknown/9.4.4",
                                    "product_id": "CSAFPID-5760037",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.4.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.4.5",
                                "product": {
                                    "name": "vers:unknown/9.4.5",
                                    "product_id": "CSAFPID-5760038",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.4.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.4.6",
                                "product": {
                                    "name": "vers:unknown/9.4.6",
                                    "product_id": "CSAFPID-5760039",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.4.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.4.7",
                                "product": {
                                    "name": "vers:unknown/9.4.7",
                                    "product_id": "CSAFPID-5760040",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/concrete5/concrete5@9.4.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<9.4.8",
                                "product": {
                                    "name": "vers:unknown/>=0|<9.4.8",
                                    "product_id": "CSAFPID-5760041"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "concrete5"
                    }
                ],
                "category": "vendor",
                "name": "concretecms"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-2994",
            "cwe": {
                "id": "CWE-352",
                "name": "Cross-Site Request Forgery (CSRF)"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configuration via group_id parameter which can leads to a security bypass since changes are saved prior to checking the CSRF token. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks z3rco for reporting",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-2994"
                },
                {
                    "category": "description",
                    "text": "Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configuration via group_id parameter which can leads to a security bypass since changes are saved prior to checking the CSRF token. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks z3rco for reporting",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-2994"
                },
                {
                    "category": "description",
                    "text": "Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configuration via group_id parameter which can leads to a security bypass since changes are saved prior to checking the CSRF token. \n\nThe Concrete CMS security team thanks z3rco for reporting",
                    "title": "github - https://github.com/advisories/GHSA-6mxw-2vhf-42g5"
                },
                {
                    "category": "description",
                    "text": "Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configuration via group_id parameter which can leads to a security bypass since changes are saved prior to checking the CSRF token. \n\nThe Concrete CMS security team thanks z3rco for reporting",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Packagist%2FGHSA-6mxw-2vhf-42g5.json?alt=media"
                },
                {
                    "category": "other",
                    "text": "0.00021",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "2.3",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "3.1",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "Is related to (a version of) an uncommon product, Is related to CWE-352 (Cross-Site Request Forgery (CSRF)), Is related to an uncommon product vendor, There is exploit data available from source Nvd, There is cwe data available from source Nvd, Exploit code publicly available",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5759390",
                    "CSAFPID-5428999",
                    "CSAFPID-5759957",
                    "CSAFPID-5759958",
                    "CSAFPID-5759959",
                    "CSAFPID-5759960",
                    "CSAFPID-5759961",
                    "CSAFPID-5759962",
                    "CSAFPID-5759963",
                    "CSAFPID-5759964",
                    "CSAFPID-5759965",
                    "CSAFPID-5759966",
                    "CSAFPID-5759967",
                    "CSAFPID-5759968",
                    "CSAFPID-5759969",
                    "CSAFPID-5759970",
                    "CSAFPID-5759971",
                    "CSAFPID-5759972",
                    "CSAFPID-5759973",
                    "CSAFPID-5759974",
                    "CSAFPID-5759975",
                    "CSAFPID-5759976",
                    "CSAFPID-5759977",
                    "CSAFPID-5759978",
                    "CSAFPID-5759979",
                    "CSAFPID-5759980",
                    "CSAFPID-5759981",
                    "CSAFPID-5759982",
                    "CSAFPID-5759983",
                    "CSAFPID-5759984",
                    "CSAFPID-5759985",
                    "CSAFPID-5759986",
                    "CSAFPID-5759987",
                    "CSAFPID-5759988",
                    "CSAFPID-5759989",
                    "CSAFPID-5759990",
                    "CSAFPID-5759991",
                    "CSAFPID-5759992",
                    "CSAFPID-5759993",
                    "CSAFPID-5759994",
                    "CSAFPID-5759995",
                    "CSAFPID-5759996",
                    "CSAFPID-5759997",
                    "CSAFPID-5759998",
                    "CSAFPID-5759999",
                    "CSAFPID-5760000",
                    "CSAFPID-5760001",
                    "CSAFPID-5760002",
                    "CSAFPID-5760003",
                    "CSAFPID-5760004",
                    "CSAFPID-5760005",
                    "CSAFPID-5760006",
                    "CSAFPID-5760007",
                    "CSAFPID-5760008",
                    "CSAFPID-5760009",
                    "CSAFPID-5760010",
                    "CSAFPID-5760011",
                    "CSAFPID-5760012",
                    "CSAFPID-5760013",
                    "CSAFPID-5760014",
                    "CSAFPID-5760015",
                    "CSAFPID-5760016",
                    "CSAFPID-5760017",
                    "CSAFPID-5760018",
                    "CSAFPID-5760019",
                    "CSAFPID-5760020",
                    "CSAFPID-5760021",
                    "CSAFPID-5760022",
                    "CSAFPID-5760023",
                    "CSAFPID-5760024",
                    "CSAFPID-5760025",
                    "CSAFPID-5760026",
                    "CSAFPID-5760027",
                    "CSAFPID-5760028",
                    "CSAFPID-5760029",
                    "CSAFPID-5760030",
                    "CSAFPID-5760031",
                    "CSAFPID-5760032",
                    "CSAFPID-5760033",
                    "CSAFPID-5760034",
                    "CSAFPID-5760035",
                    "CSAFPID-5760036",
                    "CSAFPID-5760037",
                    "CSAFPID-5760038",
                    "CSAFPID-5760039",
                    "CSAFPID-5760040",
                    "CSAFPID-5760041"
                ],
                "known_not_affected": [
                    "CSAFPID-5757538"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2994"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-2994"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-2994"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/2xxx/CVE-2026-2994.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-2994"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://github.com/advisories/GHSA-6mxw-2vhf-42g5"
                },
                {
                    "category": "external",
                    "summary": "Source raw - github",
                    "url": "https://api.github.com/advisories/GHSA-6mxw-2vhf-42g5"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Packagist%2FGHSA-6mxw-2vhf-42g5.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://documentation.concretecms.org/9-x/developers/introduction/version-history/948-release-notes"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/concretecms/concretecms/pull/12826"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2994"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/advisories/GHSA-6mxw-2vhf-42g5"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
                        "baseScore": 6.8,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-5428999",
                        "CSAFPID-5759390",
                        "CSAFPID-5759957",
                        "CSAFPID-5759958",
                        "CSAFPID-5759959",
                        "CSAFPID-5759960",
                        "CSAFPID-5759961",
                        "CSAFPID-5759962",
                        "CSAFPID-5759963",
                        "CSAFPID-5759964",
                        "CSAFPID-5759965",
                        "CSAFPID-5759966",
                        "CSAFPID-5759967",
                        "CSAFPID-5759968",
                        "CSAFPID-5759969",
                        "CSAFPID-5759970",
                        "CSAFPID-5759971",
                        "CSAFPID-5759972",
                        "CSAFPID-5759973",
                        "CSAFPID-5759974",
                        "CSAFPID-5759975",
                        "CSAFPID-5759976",
                        "CSAFPID-5759977",
                        "CSAFPID-5759978",
                        "CSAFPID-5759979",
                        "CSAFPID-5759980",
                        "CSAFPID-5759981",
                        "CSAFPID-5759982",
                        "CSAFPID-5759983",
                        "CSAFPID-5759984",
                        "CSAFPID-5759985",
                        "CSAFPID-5759986",
                        "CSAFPID-5759987",
                        "CSAFPID-5759988",
                        "CSAFPID-5759989",
                        "CSAFPID-5759990",
                        "CSAFPID-5759991",
                        "CSAFPID-5759992",
                        "CSAFPID-5759993",
                        "CSAFPID-5759994",
                        "CSAFPID-5759995",
                        "CSAFPID-5759996",
                        "CSAFPID-5759997",
                        "CSAFPID-5759998",
                        "CSAFPID-5759999",
                        "CSAFPID-5760000",
                        "CSAFPID-5760001",
                        "CSAFPID-5760002",
                        "CSAFPID-5760003",
                        "CSAFPID-5760004",
                        "CSAFPID-5760005",
                        "CSAFPID-5760006",
                        "CSAFPID-5760007",
                        "CSAFPID-5760008",
                        "CSAFPID-5760009",
                        "CSAFPID-5760010",
                        "CSAFPID-5760011",
                        "CSAFPID-5760012",
                        "CSAFPID-5760013",
                        "CSAFPID-5760014",
                        "CSAFPID-5760015",
                        "CSAFPID-5760016",
                        "CSAFPID-5760017",
                        "CSAFPID-5760018",
                        "CSAFPID-5760019",
                        "CSAFPID-5760020",
                        "CSAFPID-5760021",
                        "CSAFPID-5760022",
                        "CSAFPID-5760023",
                        "CSAFPID-5760024",
                        "CSAFPID-5760025",
                        "CSAFPID-5760026",
                        "CSAFPID-5760027",
                        "CSAFPID-5760028",
                        "CSAFPID-5760029",
                        "CSAFPID-5760030",
                        "CSAFPID-5760031",
                        "CSAFPID-5760032",
                        "CSAFPID-5760033",
                        "CSAFPID-5760034",
                        "CSAFPID-5760035",
                        "CSAFPID-5760036",
                        "CSAFPID-5760037",
                        "CSAFPID-5760038",
                        "CSAFPID-5760039",
                        "CSAFPID-5760040",
                        "CSAFPID-5760041"
                    ]
                }
            ],
            "title": "CVE-2026-2994"
        }
    ]
}