Description
Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them into iframe HTML attributes without escaping or integer casting, resulting in stored cross-site scripting. A user with edit_block permission could inject an event handler that executed script for visitors rendering the page, acting with administrative privileges where the victim was an administrator. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks sh4d0byss for reporting.
Published: 2026-09-14
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS with administrative privilege escalation
Action: Immediate Patch
AI Analysis

Impact

Concrete CMS versions 9.5.2 and earlier sanitize the YouTube block’s width and height fields only with trim(), then insert those values directly into iframe attributes without escaping or numeric casting. An attacker who can edit a block can insert an inline event handler that will be rendered in the iframe and executed in the browsers of any visitor. Because the code runs whenever the page is rendered, a victim who is an administrator can be compromised, enabling credential theft or further exploitation. This flaw is a stored cross‑site scripting vulnerability and exemplifies CWE‑79.

Affected Systems

Any Concrete CMS deployment prior to version 9.5.3 that continues to use the legacy YouTube block is affected, regardless of custom extensions that rely on the block.

Risk and Exploitability

The CVSS v4.0 score of 7.3 indicates high severity. Exploitation requires only edit_block permission, a role that may be widely available in many environmentsISA very low exploitation probability, with a score of 0.00251 (0.25%). Yet the remote and authorized block‑editing attack path suggests that risk could be significant in organizations where block‑editing permissions are not tightly controlled. Prompt patching or restriction of edit privileges reduces the attack surface.

Generated by OpenCVE AI on September 17, 2026 at 19:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to version 9.5.3 or newer to apply the vendor‑provided fix.
  • Restrict the edit_block permission to a small set of trusted administratorsside validation or sanitisation of width and height values so that only numeric input is accepted and any characters are escaped before rendering the iframe attributes.
  • As a temporary measure, remove or disable the YouTube block from publicly accessible pages until a patch is applied.

Generated by OpenCVE AI on September 17, 2026 at 19:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Mon, 14 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them into iframe HTML attributes without escaping or integer casting, resulting in stored cross-site scripting. A user with edit_block permission could inject an event handler that executed script for visitors rendering the page, acting with administrative privileges where the victim was an administrator. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks sh4d0byss for reporting.
Title Concrete CMS before 9.5.3 is vulnerable to Stored XSS in the YouTube block (vWidth/vHeight)
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-15T13:44:30.063Z

Reserved: 2026-08-27T18:18:39.738Z

Link: CVE-2026-81900

cve-icon Vulnrichment

Updated: 2026-09-15T13:44:26.026Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T23:18:48.333

Modified: 2026-09-16T20:47:10.650

Link: CVE-2026-81900

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')