Description
Concrete CMS 9.0.0 to 9.5.2 stored group folder names without sanitization and printed them unescaped on the Members > Groups dashboard page, resulting in stored cross-site scripting. The add and edit group-folder handlers stored the submitted folder name without neutralizing HTML, and the group search grid returned it without output encoding, so the Groups dashboard rendered the name as live markup. An authenticated user holding the Add Group Folder permission could store a script payload as a folder name that executed in the session of any administrator who viewed the Groups dashboard, enabling session and token theft and any action available in the administrator's context. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Lý Chấn Hưng (hunglyvn) for reporting.
Published: 2026-09-15
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting leading to administrator session hijacking
Action: Immediate Patch
AI Analysis

Impact

Concrete CMS versions 9.0.0 through 9.5.2 permit the storage of unescaped group folder names. A malicious payload can be persisted and rendered as active HTML on the Members > Groups dashboard. When an administrator views the page, the script executes inside the administrator’s browser session, enabling theft of session cookies, tokens, and the ability to perform any administrative operation.

Affected Systems

Concrete CMS 9.0.0 up to and including 9.5.2 are affected. The flaw can be triggered by any authenticated user who possesses the Add Group Folder permission, allowing the attacker to store a malicious folder name that will be displayed on the group dashboard for all administrators.

Risk and Exploitability

The CVSS v4.0 score of 7.3 denotes a high‑severity vulnerability. The EPSS score is 0.00274, indicating a low but non‑zero likelihood of exploitation, and the issue is not listed in CISA KEV. Exploitation requires an authenticated user with Add Group Folder privileges; the attacker can then inject a script that runs when any administrator opens the Groups dashboard. The attack complexity is low, the required privileges are high, and user interaction is needed only from the victim administrator, who will inadvertently execute the malicious code in their session.

Generated by OpenCVE AI on September 20, 2026 at 14:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest official Concrete CMS update that releasing an update is not possible immediately, restrict the Add Group Folder permission to a minimal set of trusted administrators.
  • Validate and encode all group folder names of executable markup.
  • Monitor the member groups interface for unexpected or suspicious script tags in folder names.

Generated by OpenCVE AI on September 20, 2026 at 14:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Concrete CMS 9.0.0 to 9.5.2 stored group folder names without sanitization and printed them unescaped on the Members > Groups dashboard page, resulting in stored cross-site scripting. The add and edit group-folder handlers stored the submitted folder name without neutralizing HTML, and the group search grid returned it without output encoding, so the Groups dashboard rendered the name as live markup. An authenticated user holding the Add Group Folder permission could store a script payload as a folder name that executed in the session of any administrator who viewed the Groups dashboard, enabling session and token theft and any action available in the administrator's context. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Lý Chấn Hưng (hunglyvn) for reporting.
Title Concrete CMS 9.0 to 9.5.2 is vulnerable to Stored XSS via group folder name on the Members > Groups dashboard
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-15T19:18:41.365Z

Reserved: 2026-08-27T18:18:39.738Z

Link: CVE-2026-81899

cve-icon Vulnrichment

Updated: 2026-09-15T19:18:36.947Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:19:26.930

Modified: 2026-09-16T19:16:15.097

Link: CVE-2026-81899

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')