Impact
Concrete CMS 9.5.2 and earlier contain a stored DOM-based XSS flaw, designated as CWE-79, that allows an editor to inject malicious scripts via the image caption field. The bundled Magnific Popup script treats the caption as HTML and injects it with jQuery .append() when the lightbox is opened. Consequently, when any visitor opens the image lightbox, the malicious code runs in their browser, allowing the attacker to execute arbitrary scripts, exfiltrate data, or conduct phishing attacks.
Affected Systems
The vulnerability applies to Concrete CMS installations using version 9.5.2 or older that include the Gallery block. The image caption field is directly exposed to editors with page‑editing rights.
Risk and Exploitability
The CVSS v4.0 score of 8.5 denotes a high severity, while the EPSS score of less than 1% implies a low current likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Nevertheless, an attacker with page‑editing rights can embed malicious code that will later be executed automatically for every visitor who triggers the lightbox, making the risk tangible for any publication with lax edit permissions.
OpenCVE Enrichment