Announcing Concrete CMS 9.5.1 Release

Announcing Concrete CMS 9.5.1 Release


May 27, 2026
by jessicadunbar

We are happy to announce Concrete CMS 9.5.1. This one is important: if you are running any earlier version of Concrete, you should update.

The bulk of this release is security fixes. Our security team and a group of independent researchers found and reported a significant number of vulnerabilities, and we fixed all of them. The issues ranged from places where private content could be accessed without logging in, to cases where a malicious administrator could do more damage than they should be able. None of these require any action from your end other than updating. Once you are on 9.5.1, they are closed.

We do not take security lightly. Clients depend on Concrete to stay safe, and that expectation shapes how seriously we treat every report that comes in. If you reported an issue that made it into this release, thank you. The full list of CVEs and researcher credits is in the release notes and security announcement.

Beyond security, 9.5.1 also includes some quality of life improvements: the Document Library loads faster on sites with large file libraries, system pages can no longer be accidentally moved or copied, and anonymous surveys now check IP addresses in addition to cookies to prevent duplicate votes.

One thing worth knowing if you manage your own hosting: if your server has proc\_open disabled, the Symfony Mailer change introduced in 9.5.0 may affect how mail is sent. Configuring an external SMTP server will resolve it.

To everyone who reported vulnerabilities responsibly: thank you. This is how open source security is supposed to work.

Read the full release notes

The full list of CVEs is on the security page for anyone who needs the details.