Impact
Concrete CMS versions 9.5.2 and earlier render remote RSS feed item titles without escaping HTML, allowing an attacker who can influence a syndicated feed to embed script that executes whenever any visitor views the page. The resulting client‑side code execution can be used to hijack sessions, deface the site, or perform other malicious actions against users, including site administrators, without needing any site account.
Affected Systems
Concrete CMS product lines older than version 9.5.3 are affected. All installations that include external RSS feeds are potentially vulnerable until the core is updated beyond 9.5.3.
Risk and Exploitability
The CVSS v4.0 score of 6.0 indicates a moderate severity. The EPSS score is less than 1%, reflecting a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via control of a syndicated feed that the CMS consumes, permitting any external feed source to inject malicious titles.
OpenCVE Enrichment