Description
Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot dialog. The custom_slot save_template endpoint authorizes the request only against the target board instance (canEditBoardContents()) and then persists the client-supplied selectedTemplateOption[collection] verbatim, rather than rebuilding the content object collection server-side and verifying that each item belongs to the authorized board's data pool. A user with permission to edit the contents of at least one board instance can therefore store a forged summary object whose description field carries a JavaScript-bearing HTML payload. The default summary template renders the description field without output encoding, so the payload executes in the browser of any user who views the affected board slot, including anonymous front-end visitors and dashboard users who preview the resulting rule or block. This can enable session or action takeover and escalation toward an administrator. Concrete CMS versions below 9 do not include the Boards feature and are not affected. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.8 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.
Published: 2026-09-11
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS enabling session or action takeover
Action: Patch Now
AI Analysis

Impact

Concrete CMS versions 9.0.0 through 9.5.2 contain a stored cross‑site scripting vulnerability in the Board Custom Slot save_template endpoint. The endpoint only verifies that the requester can edit the target board (canEditBoardContents()) and then stores the client‑supplied selectedTemplateOption[collection] data directly, without re‑constructing the content or confirming that the items belong to the board’s data pool. Because the default summary template renders the description field without output encoding, an attacker who can edit a board can insert a malicious summary whose description contains JavaScript‑bearing HTML. When that board slot is viewed, the payload executes in the browser of any user who sees the board, including anonymous front‑end visitors and logged‑in dashboard users, potentially enabling session hijacking or higher‑privilege activity.

Affected Systems

The affected product is Concrete CMS, specifically versions 9.0.0 to 9.5.2. Earlier Concrete CMS releases prior to 9.0 do not include the Boards feature and are not affected.

Risk and Exploitability

The flaw carries a CVSS v4.0 score of 5.8, reflecting moderate severity, while its EPSS score is below 1%, indicating a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. A successful exploit requires the attacker to have edit permissions on at least one board, after which the stored XSS can affect any visitor of the board slot, providing an opportunity for session or action takeover and possible escalation to administrative credentials.

Generated by OpenCVE AI on September 21, 2026 at 04:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to the latest available version that addresses the Boards Custom Slot issue; check the vendor’s release notes for a corresponding fix.
  • Limit board editing rights to trusted users only to reduce the attack surface.
  • As a temporary countermeasure, disable the Boards feature or remove custom_slot functionality for users lacking high‑level permissions.
  • Enforce server‑side output encoding for the summary description field before rendering to prevent execution of embedded scripts.

Generated by OpenCVE AI on September 21, 2026 at 04:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Sat, 12 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot dialog. The custom_slot save_template endpoint authorizes the request only against the target board instance (canEditBoardContents()) and then persists the client-supplied selectedTemplateOption[collection] verbatim, rather than rebuilding the content object collection server-side and verifying that each item belongs to the authorized board's data pool. A user with permission to edit the contents of at least one board instance can therefore store a forged summary object whose description field carries a JavaScript-bearing HTML payload. The default summary template renders the description field without output encoding, so the payload executes in the browser of any user who views the affected board slot, including anonymous front-end visitors and dashboard users who preview the resulting rule or block. This can enable session or action takeover and escalation toward an administrator. Concrete CMS versions below 9 do not include the Boards feature and are not affected. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.8 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.
Title Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot save_template via Unescaped Summary Description
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-11T19:33:33.148Z

Reserved: 2026-08-27T18:21:25.200Z

Link: CVE-2026-81911

cve-icon Vulnrichment

Updated: 2026-09-11T19:33:26.571Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T20:19:13.687

Modified: 2026-09-18T19:00:06.357

Link: CVE-2026-81911

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:30:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')