Description
In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stored XSS in Express association views. A user able to submit an Address attribute could execute script in the session of any dashboard user who opened the affected entry. The unescaped branch was reachable because a non-required Address attribute accepted a blank country, and because several Express association templates (for example concrete/elements/express/form/view/dashboard/association.php) echoed the association label mask without applying h(). The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.5 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting in dashboard user sessions
Action: Patch Now
AI Analysis

Impact

Concrete CMS versions before 9.5.3 contain a stored Cross‑Site Scripting vulnerability that arises when an Address attribute is submitted without a country. The country‑less formatter bypasses HTML‑escaping, and one or more Express association templates echo the association label mask without sanitisation. This allows attacker to inject arbitrary JavaScript, which then runs in the browser context of any dashboard user who opens the affected entry. The impact is the potential theft of session or execution of further malicious actions on behalf of the victim.

Affected Systems

All installations of Concrete CMS running a version earlier than 9.5.3 are vulnerable. The flaw resides in Express association views, such as concrete/elements/express/form/view/dashboard/association.php, where the absence of a country field allows unescaped content to be rendered directly into the page.

Risk and Exploitability

The CVSS v4.0 score of 7.5 indicates high severity with distant network access, low complexity, and user interaction. The EPSS score of less than 1% indicates low analysis. The vulnerability is not listed in the CISA KEV catalog. Attackers are likely to exploit the flaw by submitting a contrived Address attribute through a public or authenticated form; once stored, the malicious script executes whenever a dashboard user views the entry, enabling credential theft, session hijacking, or defacement.

Generated by OpenCVE AI on September 20, 2026 at 15:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to version 9.5.3 or newer
  • Modify Express association templates to escape Address attribute values, for example by wrapping echoes with h() or htmlentities
  • Restrict the Address attribute configuration to enforce a country value or disallow blank country submissions

Generated by OpenCVE AI on September 20, 2026 at 15:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Tue, 15 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stored XSS in Express association views. A user able to submit an Address attribute could execute script in the session of any dashboard user who opened the affected entry. The unescaped branch was reachable because a non-required Address attribute accepted a blank country, and because several Express association templates (for example concrete/elements/express/form/view/dashboard/association.php) echoed the association label mask without applying h(). The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.5 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Title Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via country-less Address attribute in Express association views
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-20T00:45:43.680Z

Reserved: 2026-08-27T18:18:39.738Z

Link: CVE-2026-81898

cve-icon Vulnrichment

Updated: 2026-09-20T00:42:18.158Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:19:26.800

Modified: 2026-09-20T01:16:30.180

Link: CVE-2026-81898

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:45:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')