Impact
Concrete CMS 9.x (prior to version 9.5.3) contains a stored cross‑site scripting flaw in the Feature, Feature Link, Hero Image, and Image blocks; the flaw allows a user with page‑editing permissions to store a crafted external link that breaks out of the link markup and injects arbitrary JavaScript. The injected script is rendered when the page is viewed, previewed, or edited again, enabling the script to run in the browser session of any user who subsequently visits the affected page, which can lead to session hijacking and privilege escalation up to full administrative takeover. Concrete CMS 8.x (prior to version 8.5.21) has an identical vulnerability in the feature and image blocks.
Affected Systems
Concrete CMS 9.0–9.5.3 and older 9.x releases, as well as Concrete CMS 8.0–8.5.20 fail to validate or escape external link URLs.
Risk and Exploitability
The CVSS v4.0 score of 8.5 indicates high severity. Exploitation requires an authenticated user with page‑editing permissions, so attackers must first obtain or compromise such an account. Once an XSS payload is stored, the page can lose their session, but the issue is not listed in the CISA KEV catalog, and the combination of a high severity metric and the need for legitimate edit rights makes the risk significant for operators who expose editing capabilities to broad user bases. The EPSS score of < 1% indicates a very low probability that this vulnerability will be actively exploited in the wild.
OpenCVE Enrichment