Description
Concrete CMS RSS Displayer block below version 9.5.3 rendered remote feed item titles without HTML escaping, resulting in stored cross-site scripting. An attacker able to control a title in a syndicated feed could execute script in the site origin for any visitor to the affected page, including administrators, without holding an account on that site. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.0 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.
Published: 2026-09-11
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross-site scripting
Action: Patch
AI Analysis

Impact

Concrete CMS versions 9.5.2 and earlier render remote RSS feed item titles without escaping HTML, allowing an attacker who can influence a syndicated feed to embed script that executes whenever any visitor views the page. The resulting client‑side code execution can be used to hijack sessions, deface the site, or perform other malicious actions against users, including site administrators, without needing any site account.

Affected Systems

Concrete CMS product lines older than version 9.5.3 are affected. All installations that include external RSS feeds are potentially vulnerable until the core is updated beyond 9.5.3.

Risk and Exploitability

The CVSS v4.0 score of 6.0 indicates a moderate severity. The EPSS score is less than 1%, reflecting a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via control of a syndicated feed that the CMS consumes, permitting any external feed source to inject malicious titles.

Generated by OpenCVE AI on September 21, 2026 at 04:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to version 9.5.3 or newer.
  • If updating is not possible, edit the RSS Displayer template or configuration to escape or strip HTML from feed titles before rendering.
  • Restrict the RSS Displayer block to trusted users or remove it from public pages until the vulnerability is fixed.

Generated by OpenCVE AI on September 21, 2026 at 04:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS RSS Displayer block below version 9.5.3 rendered remote feed item titles without HTML escaping, resulting in stored cross-site scripting. An attacker able to control a title in a syndicated feed could execute script in the site origin for any visitor to the affected page, including administrators, without holding an account on that site. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.0 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.
Title Concrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Block via Unescaped Remote Feed Item title
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-11T19:26:50.432Z

Reserved: 2026-07-30T18:04:50.762Z

Link: CVE-2026-68528

cve-icon Vulnrichment

Updated: 2026-09-11T19:26:42.479Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T18:16:57.643

Modified: 2026-09-11T20:17:22.430

Link: CVE-2026-68528

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:30:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')