Description
Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-image Caption field because the bundled Magnific Popup lightbox script (concrete/js/features/imagery/frontend.js) re-parses the attribute-decoded caption as HTML through jQuery's .append() in titleSrc instead of inserting it as text. A user with permission to edit a page containing a Gallery block can store a caption that executes in the browser of any visitor who opens that image's lightbox. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 8.5 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.
Published: 2026-09-15
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored DOM-based XSS
Action: Apply Patch
AI Analysis

Impact

Concrete CMS 9.5.2 and earlier contain a stored DOM-based XSS flaw, designated as CWE-79, that allows an editor to inject malicious scripts via the image caption field. The bundled Magnific Popup script treats the caption as HTML and injects it with jQuery .append() when the lightbox is opened. Consequently, when any visitor opens the image lightbox, the malicious code runs in their browser, allowing the attacker to execute arbitrary scripts, exfiltrate data, or conduct phishing attacks.

Affected Systems

The vulnerability applies to Concrete CMS installations using version 9.5.2 or older that include the Gallery block. The image caption field is directly exposed to editors with page‑editing rights.

Risk and Exploitability

The CVSS v4.0 score of 8.5 denotes a high severity, while the EPSS score of less than 1% implies a low current likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Nevertheless, an attacker with page‑editing rights can embed malicious code that will later be executed automatically for every visitor who triggers the lightbox, making the risk tangible for any publication with lax edit permissions.

Generated by OpenCVE AI on September 20, 2026 at 15:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Limit edit rights on Gallery blocks to trusted administrators only.
  • Implement server‑side sanitization on the caption field to escape or strip disallowed HTML before storage.
  • Upgrade to the latest supported Concrete CMS release when an official patch becomes available.

Generated by OpenCVE AI on September 20, 2026 at 15:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Tue, 15 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Tue, 15 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-image Caption field because the bundled Magnific Popup lightbox script (concrete/js/features/imagery/frontend.js) re-parses the attribute-decoded caption as HTML through jQuery's .append() in titleSrc instead of inserting it as text. A user with permission to edit a page containing a Gallery block can store a caption that executes in the browser of any visitor who opens that image's lightbox. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 8.5 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.
Title Concrete CMS 9.5.2 and below is vulnerable to Stored DOM-based Cross-site Scripting (XSS) in the Gallery block image Caption field
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-22T18:07:28.458Z

Reserved: 2026-08-27T18:18:39.736Z

Link: CVE-2026-81894

cve-icon Vulnrichment

Updated: 2026-09-22T18:05:58.298Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T17:17:27.543

Modified: 2026-09-22T19:16:52.367

Link: CVE-2026-81894

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')