Description
Concrete CMS 9.0.0 through 9.5.3 is vulnerable to stored XSS via the custom page alias name (customAliasName) because the Edit Alias dialog applied only trim() to the submitted value and performed no input neutralization. An authenticated user holding canWrite (editor) permission on a page could store a malicious alias name that was later rendered unescaped in the administrative Sitemap panel, where it executed automatically in any administrator or editor session that opened the panel, allowing an editor to escalate to administrator through the victim's active session. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N. Thanks Nguyen Manh Thuan for reporting.
Published: 2026-09-14
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS that can lead to privilege escalation to administrator
Action: Patch Now
AI Analysis

Impact

Concrete CMS versions 9.0.0 through 9.5.3 do not neutralize custom page alias names. The Edit Alias dialog accepts the raw input after only trimming whitespace, so an authenticated user with canWrite permission can store an alias containing malicious script content. When an admin or editor later opens the Sitemap panel, the unsanitized alias is rendered unescaped in the page title area and the embedded script executes automatically, allowing the user to elevate privileges within the victim’s active session. The weakness is a classic input validation failure that results in stored cross‑site scripting.

Affected Systems

All installations of Concrete CMS that include the affected version range, namely 9.0.0 through 9.5.3. Any site where page administrators can edit alias names and grant canWrite rights to editors is vulnerable.

Risk and Exploitability

The CVSS v4.0 score of 7.3 indicates a high severity vulnerability. The EPSS score of less than 1% points to a low overall exploitation probability across the population, yet the vulnerability can be activated by any authenticated editor who can adjust a page alias, making it likely to be exploited in environments where such permissions are common. Though it is not listed in the CISA KEV catalog, this stored XSS can lead to privilege escalation to administrator within the victim’s active session.

Generated by OpenCVE AI on September 17, 2026 at 19:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to the latest available version, ensuring the alias input is properly validated and escaped.
  • Restrict the canWrite permission for alias editing to trusted users or disable alias editing entirely until a patch is applied.
  • Sanitize stored alias values or escape them on output to mitigate the XSS risk.

Generated by OpenCVE AI on September 17, 2026 at 19:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Concrete CMS 9.0.0 through 9.5.3 is vulnerable to stored XSS via the custom page alias name (customAliasName) because the Edit Alias dialog applied only trim() to the submitted value and performed no input neutralization. An authenticated user holding canWrite (editor) permission on a page could store a malicious alias name that was later rendered unescaped in the administrative Sitemap panel, where it executed automatically in any administrator or editor session that opened the panel, allowing an editor to escalate to administrator through the victim's active session. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N. Thanks Nguyen Manh Thuan for reporting.
Title Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Custom Page Alias Name
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-15T19:15:09.790Z

Reserved: 2026-07-28T18:02:01.020Z

Link: CVE-2026-18117

cve-icon Vulnrichment

Updated: 2026-09-15T19:15:02.493Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T22:16:57.483

Modified: 2026-09-29T19:17:27.670

Link: CVE-2026-18117

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')