Description
In Concrete CMS 9.2.0 through 9.5.2, the REST API page update endpoint (PUT /ccm/api/1.0/pages/{cID}) did not enforce page-property, page-template, or page-type authorization. A user granted only content-editing rights on a page could therefore alter its properties, template, and type through the API, and could set the header_extra_content attribute, which is rendered unescaped into the head element of every page, to persist JavaScript that executed in the browser of every visitor, including higher-privileged reviewers who approve the page version. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.2 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Published: 2026-09-14
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting via unauthorized page updates
Action: Patch
AI Analysis

Impact

The vulnerability allows a user with content‑editing rights to modify page properties, templates, and types through the REST API endpoint PUT /ccm/api/1.0/pages/{cID}. Because the endpoint does not enforce authorization on the header_extra_content field, an attacker can persist malicious JavaScript into the head of every page. This JavaScript is rendered unescaped, giving the attacker a stored cross‑site scripting weakness that affects all visitors, including administrators who approve page versions.

Affected Systems

Concrete CMS installations running version 9.2.0 up to and including 9.5.2 are affected. These are the only versions documented as vulnerable; newer releases are not impacted.

Risk and Exploitability

The CVSS score of 7.2 indicates a medium‑to‑high severity. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, but the REST API is exposed over HTTP(S) so an attacker who can authenticate with a content‑editing account could reach the vulnerable endpoint. This is the inferred attack vector. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 20, 2026 at 21:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to the latest available version that resolves the missing authorization checks on the page update API.
  • Restrict or revoke REST API access for user roles that only have content‑editing rights, ensuring that only administrators can change page properties, templates, and types.
  • Review existing pages and sanitize or remove any malformed header_extra_content values that may contain injected JavaScript.

Generated by OpenCVE AI on September 20, 2026 at 21:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description In Concrete CMS 9.2.0 through 9.5.2, the REST API page update endpoint (PUT /ccm/api/1.0/pages/{cID}) did not enforce page-property, page-template, or page-type authorization. A user granted only content-editing rights on a page could therefore alter its properties, template, and type through the API, and could set the header_extra_content attribute, which is rendered unescaped into the head element of every page, to persist JavaScript that executed in the browser of every visitor, including higher-privileged reviewers who approve the page version. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.2 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Title Concrete CMS 9.2.0 to 9.5.2 is vulnerable to stored XSS due to missing authorization in the `PUT /pages/{cID}` endpoint
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-15T14:23:36.718Z

Reserved: 2026-08-27T18:18:39.738Z

Link: CVE-2026-81901

cve-icon Vulnrichment

Updated: 2026-09-15T14:23:34.013Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:26.123

Modified: 2026-09-18T19:17:29.047

Link: CVE-2026-81901

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:45:04Z

Weaknesses