Description
Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image, and Image blocks and before Concrete 8.5.21 in the feature and Image blocks because the external link URL was insufficiently validated by the link filter and was rendered without output escaping. A user with page-editing permissions (such as Add Block combined with Edit Contents on a single page) could store a crafted external link value that broke out of the link markup and injected arbitrary JavaScript. The script executed in the browser session of any user who subsequently viewed, previewed, or edited the affected page, which could lead to session hijacking and escalation of privileges up to full administrative takeover. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 8.5 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks to KhanMarshai for reporting this issue.
Published: 2026-09-15
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Stored XSS
Action: Patch Immediately
AI Analysis

Impact

Concrete CMS 9.x (prior to version 9.5.3) contains a stored cross‑site scripting flaw in the Feature, Feature Link, Hero Image, and Image blocks; the flaw allows a user with page‑editing permissions to store a crafted external link that breaks out of the link markup and injects arbitrary JavaScript. The injected script is rendered when the page is viewed, previewed, or edited again, enabling the script to run in the browser session of any user who subsequently visits the affected page, which can lead to session hijacking and privilege escalation up to full administrative takeover. Concrete CMS 8.x (prior to version 8.5.21) has an identical vulnerability in the feature and image blocks.

Affected Systems

Concrete CMS 9.0–9.5.3 and older 9.x releases, as well as Concrete CMS 8.0–8.5.20 fail to validate or escape external link URLs.

Risk and Exploitability

The CVSS v4.0 score of 8.5 indicates high severity. Exploitation requires an authenticated user with page‑editing permissions, so attackers must first obtain or compromise such an account. Once an XSS payload is stored, the page can lose their session, but the issue is not listed in the CISA KEV catalog, and the combination of a high severity metric and the need for legitimate edit rights makes the risk significant for operators who expose editing capabilities to broad user bases. The EPSS score of < 1% indicates a very low probability that this vulnerability will be actively exploited in the wild.

Generated by OpenCVE AI on September 20, 2026 at 15:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to 9.5.4 or newer, or to 8.5.21 if using a version 8.x release.
  • Limit page‑editing permissions to a minimal set of trusted users or low‑privilege accounts.
  • Apply an intermediate security patch that sanitizes external link URLs before rendering; if unavailable, configure the site to remove or hide the vulnerable blocks until a full upgrade can be applied.

Generated by OpenCVE AI on September 20, 2026 at 15:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Tue, 15 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image, and Image blocks and before Concrete 8.5.21 in the feature and Image blocks because the external link URL was insufficiently validated by the link filter and was rendered without output escaping. A user with page-editing permissions (such as Add Block combined with Edit Contents on a single page) could store a crafted external link value that broke out of the link markup and injected arbitrary JavaScript. The script executed in the browser session of any user who subsequently viewed, previewed, or edited the affected page, which could lead to session hijacking and escalation of privileges up to full administrative takeover. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 8.5 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks to KhanMarshai for reporting this issue.
Title Concrete CMS below 9.5.4 allows privilege escalation because adding users and assigning groups do not require additional identity verification
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-22T18:10:34.740Z

Reserved: 2026-07-28T18:01:54.873Z

Link: CVE-2026-18111

cve-icon Vulnrichment

Updated: 2026-09-22T18:10:30.371Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-15T17:17:11.247

Modified: 2026-09-22T19:16:42.030

Link: CVE-2026-18111

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:30:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function