Description
In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not validate the anti-CSRF token. By causing an authenticated administrator to submit a forged cross-site request, a remote attacker without credentials could write attacker-controlled headline and body values to an existing Express form Text control. Those values were emitted without output encoding by the Express form Text element, so the injected markup executed as persistent JavaScript for any administrator who later opened the affected entry, resulting in stored cross-site scripting. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.7 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross‑site scripting via missing anti‑CSRF token in Concrete CMS
Action: Patch
AI Analysis

Impact

Concrete CMS versions earlier than 9.5.3 do not verify the anti‑CSRF token for the save_control action in the Express entities dashboard. An attacker can cause an authenticated administrator to submit a forged request that writes attacker‑controlled markup into the headline and body fields of an existing Express form Text control. These fields are rendered without output encoding, so the embedded script runs as persistent JavaScript whenever any administrator opens the affected entry.

Affected Systems

Concrete CMS installations running any version below 9.5.3 are affected. The flaw resides in the Express form Text control within the Express entities module and requires that the target system host this module.

Risk and Exploitability

The CVSS score of 7.7 indicates high severity, reflecting a significant threat if a malicious script is executed by an administrator. The EPSS score is under 1 %, suggesting a low likelihood of exploitation in the wild at present, but the vulnerability is not listed in CISA’s KEV catalog. An attacker can achieve this via a web‑based CSRF attack, requiring an authenticated administrator to submit the forged request.

Generated by OpenCVE AI on September 20, 2026 at 16:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to version 9.5.3 or later, which restores anti‑CSRF token validation (CWE-352).
  • Ensure that output from the Express form Text control is properly HTML‑encoded or sanitized to prevent script execution (CWE-79).
  • Implement a Content Security Policy that blocks inline scripts or restricts script sources to reduce the impact of any stored XSS pending a patch.

Generated by OpenCVE AI on September 20, 2026 at 16:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Tue, 15 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Tue, 15 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not validate the anti-CSRF token. By causing an authenticated administrator to submit a forged cross-site request, a remote attacker without credentials could write attacker-controlled headline and body values to an existing Express form Text control. Those values were emitted without output encoding by the Express form Text element, so the injected markup executed as persistent JavaScript for any administrator who later opened the affected entry, resulting in stored cross-site scripting. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.7 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Title Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via Express form Text control save_control
Weaknesses CWE-352
CWE-79
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-22T18:13:54.596Z

Reserved: 2026-08-27T18:18:39.737Z

Link: CVE-2026-81897

cve-icon Vulnrichment

Updated: 2026-09-22T18:13:49.888Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T17:17:27.997

Modified: 2026-09-22T19:16:52.777

Link: CVE-2026-81897

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:15:18Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')