Description
In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing them into the page, so a user who could create or rename pages could store a script through a child page name and have it run in the browser of any visitor, editor, or administrator who viewed the navigation and opened the affected dropdown. In the Concrete CMS origin, the script executed with the victim's privileges and could read same-origin content or perform actions available to that user. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.5 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks labixiaoxin97 for reporting.
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

Concrete CMS versions 9.0 to 9.5.2 are vulnerable because the Top Navigation Bar block does not HTML‑escape dropdown child page names before rendering them. A user who can create or rename pages can insert JavaScript into a child page name, which is then stored and executed in the browsers of any visitor, editor, or administrator who views the navigation. The injected script runs with the privileges of the viewer and can read same‑origin content or perform any actions available to that user, creating a high‑impact compromise.

Affected Systems

The affected product is Concrete CMS, specifically versions 9.0 through 9.5.2 where the Top Navigation Bar block is present. Users of these releases should verify whether their installations use this block.

Risk and Exploitability

The CVSS v4.0 score for this flaw is 7.5, indicating a high severity. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw via persistent malicious input on page names, a vector that requires the attacker to have rights to create or rename pages. If such access is available, the stored script can be triggered simply by a visitor browsing the affected navigation bar.

Generated by OpenCVE AI on September 20, 2026 at 14:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to version 9.5.3 or later, which includes proper HTML escaping for dropdown child page names in the Top Navigation Bar block.
  • If an upgrade cannot be applied immediately, restrict the ability to create or rename pages to trusted administrators only to limit the opportunity for malicious script injection.
  • Audit existing page names in the navigation bar for embedded scripts and remove any suspicious content before applying the patch.

Generated by OpenCVE AI on September 20, 2026 at 14:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Tue, 15 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing them into the page, so a user who could create or rename pages could store a script through a child page name and have it run in the browser of any visitor, editor, or administrator who viewed the navigation and opened the affected dropdown. In the Concrete CMS origin, the script executed with the victim's privileges and could read same-origin content or perform actions available to that user. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.5 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks labixiaoxin97 for reporting.
Title Concrete CMS 9.0 to 9.5.2 is vulnerable to Stored XSS in the Top Navigation Bar Block via Dropdown Child Page Names
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-20T00:45:43.542Z

Reserved: 2026-07-28T18:01:57.257Z

Link: CVE-2026-18113

cve-icon Vulnrichment

Updated: 2026-09-20T00:42:15.994Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:17:17.770

Modified: 2026-09-20T01:16:28.450

Link: CVE-2026-18113

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:00:11Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')