Description
Concrete CMS versions 9.0.0 to 9.5.2 stored the Page Container icon value submitted through the dashboard without validating it against the set of known container icons. The unvalidated value was later concatenated into the src attribute of an img tag by a helper that did not encode attribute output, and was rendered raw in the Containers dashboard list and editor views. A user with delegated access to the Page Containers dashboard could store a crafted icon value that broke out of the src attribute and executed script in the authenticated session of another editor or administrator who viewed the list, enabling session token theft and privileged dashboard actions. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.0 with vector CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Andrew Gonzalez for reporting.
Published: 2026-09-14
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting (XSS) leading to session hijacking and privileged dashboard actions
Action: Immediate Patch
AI Analysis

Impact

Concrete CMS versions 9.0.0 through 9.5.2 accept a Page Container icon value without validation and later embed it directly into an img tag’s src attribute. Because the output helper does not encode the attribute, a crafted value can break out of the src context and inject arbitrary script that runs in the authenticated context of another editor or administrator. This allows an attacker to steal session tokens and perform privileged dashboard actions while logged in.

Affected Systems

All sites running Concrete CMS between versions 9.0.0 and 9.5.2 are affected, including any deployment that has not applied a later release. Users with delegated access to the Page Containers dashboard are the ones who can introduce the malicious icon value.

Risk and Exploitability

The CVSS score of 7.0 indicates moderate to high severity. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not in the CISA KEV catalog. The exploit requires an authenticated attack with delegated dashboard permissions, so the attack surface is limited to users who can edit page containers. Nevertheless, once a malicious icon is stored, any subsequent dashboard view by an editor or administrator will execute the injected script, providing a foothold for session hijacking or further privilege escalation.

Generated by OpenCVE AI on September 20, 2026 at 21:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Concrete CMS release (9.5.3 or newer) that removes the unvalidated icon handling and properly encodes all attributes.
  • If no patch is immediately available, restrict Page Container icon selection to the pre‑approved set via custom validation or use an input filter to block characters that could break out of the src attribute, such as single quotes, double quotes, and angle brackets.
  • Ensure that users who have delegated access to the Page Containers dashboard have the minimum permissions necessary and monitor for anomalous icon values or unexpected script execution in the editor interface.

Generated by OpenCVE AI on September 20, 2026 at 21:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Concrete CMS versions 9.0.0 to 9.5.2 stored the Page Container icon value submitted through the dashboard without validating it against the set of known container icons. The unvalidated value was later concatenated into the src attribute of an img tag by a helper that did not encode attribute output, and was rendered raw in the Containers dashboard list and editor views. A user with delegated access to the Page Containers dashboard could store a crafted icon value that broke out of the src attribute and executed script in the authenticated session of another editor or administrator who viewed the list, enabling session token theft and privileged dashboard actions. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.0 with vector CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Andrew Gonzalez for reporting.
Title Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS via Page Container icon
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-15T14:45:47.911Z

Reserved: 2026-08-27T18:18:39.738Z

Link: CVE-2026-81903

cve-icon Vulnrichment

Updated: 2026-09-15T14:45:44.899Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:26.400

Modified: 2026-09-18T19:12:09.993

Link: CVE-2026-81903

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:00:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')