Description
Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in the workflow approval and deletion notifications shown in the dashboard "Waiting For Me" block. A registered user permitted to add events to a calendar governed by an approval workflow could submit an event whose name contained a script payload, which then executed in an administrator's browser when the pending request was displayed and could be used to create a new administrator account. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks v01demort for reporting.
Published: 2026-09-14
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS allowing privilege escalation
Action: Immediate Patch
AI Analysis

Impact

The flaw occurs when a calendar event name is stored without sanitization and later displayed in workflow approval or deletion notifications without HTML escaping. Because these notifications appear in the dashboard block, a registered user who can add events to a calendar governed by an approval workflow can submit a name containing a malicious script. When an administrator views the pending request, the embedded script executes in the administrator’s browser context, allowing the attacker to create a new administrator account and thus gain full control of the site. The vulnerability is thus a stored cross‑site scripting flaw that enables remote code execution within an administrator’s browser and elevation of privilege.

Affected Systems

Concrete CMS versions from 8.3.0 up to and including 9.5.2 are affected. No patched or fixed version is listed in the available data.

Risk and Exploitability

The CVSS v4.0 score of 7.3 indicates a high severity. The exploit requires the attacker to be a registered user able the notification; thus the attack is local to the administrative interface and requires user interaction. The EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV catalog, which suggests that exploitation is not currently widespread but remains possible. Given the potential for privilege escalation, the risk to systems with an active approval workflow remains significant.

Generated by OpenCVE AI on September 17, 2026 at 19:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to a version newer than 9.5.2 or apply any official patch if it becomes available.
  • If upgrading immediately is not feasible, disable the workflow approval notifications for calendar event creation until the vendor releases a fix.
  • Implement input validation or output encoding for calendar event names to prevent script injection, following best practices for CWE‑79 mitigations.

Generated by OpenCVE AI on September 17, 2026 at 19:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Mon, 14 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in the workflow approval and deletion notifications shown in the dashboard "Waiting For Me" block. A registered user permitted to add events to a calendar governed by an approval workflow could submit an event whose name contained a script payload, which then executed in an administrator's browser when the pending request was displayed and could be used to create a new administrator account. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks v01demort for reporting.
Title Concrete CMS 8.3.0 to 9.5.2 is vulnerable to Stored XSS in Calendar Event Name via Workflow Approval Notifications
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-15T13:39:59.044Z

Reserved: 2026-07-28T18:02:00.045Z

Link: CVE-2026-18116

cve-icon Vulnrichment

Updated: 2026-09-15T13:39:14.906Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T23:17:15.683

Modified: 2026-09-21T17:49:50.103

Link: CVE-2026-18116

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')