Description
Concrete CMS below 9.5.3 does not apply HTML output escaping to the file description and tags fields when rendering the Document Library block, so a user with permission to edit file properties could store a script payload that executed in the browser of any visitor to a page displaying the block with the description or tags column enabled, including unauthenticated visitors. Successful exploitation could allow theft of session data or actions performed in the visitor's context. The block controller returned the description and tags values without the h() escaping already applied to the title column, and the block view template wrote the returned value directly into the results table The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N. Thanks Nguyen Manh Thuan for reporting.
Published: 2026-09-11
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

Concrete CMS versions file description and tags fields in the Document Library block without applying HTML escaping, allowing an editor to persist malicious script payloads in the database. When a page containing the block is viewed, the unescaped content is injected into the page’s HTML and executed in the visitor’s browser. This vulnerability can be used to steal session tokens or perform actions on behalf of the victim, thereby compromising confidentiality and integrity for anyone who accesses the affected block. The weakness is a classic Stored XSS, classified as CWE‑79.

Affected Systems

All installations running Concrete CMS earlier than 9.5.3 are affected. The issue resides in the core Document Library block component, and any page displaying that block with the description or tags columns enabled exposes the risk. Users with edit permissions on file properties can inject the payload; unauthenticated visitors can be impacted if they view pages that include the vulnerable block.

Risk and Exploitability

The CVSS v4.0 score of 5.1 indicates a moderate severity. The attack vector is network‑public, but an attacker must first have edit rights to file properties. The EPSS score of < 1% suggests a very low likelihood of exploitation in the editor role and simply uploads the malicious content; once stored, the payload is served to all visitors, including unauthenticated users.

Generated by OpenCVE AI on September 15, 2026 at 20:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Concrete CMS 9.5.3 or any later release that implements proper HTML escaping for the file description and tags who should not be able to modify or upload content for publicly accessible blocks.
  • Configure the Document Library block to disable the description or tags columns, or remove the block from pages that are reachable by unauthenticated visitors to prevent stored payloads from rendering.
  • If upgrading is not immediately possible, manually sanitize existing content by removing or encoding any <script> tags from the file descriptions and tags fields before rendering, or modify the block template to apply $h() escaping to these fields.

Generated by OpenCVE AI on September 15, 2026 at 20:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS below 9.5.3 does not apply HTML output escaping to the file description and tags fields when rendering the Document Library block, so a user with permission to edit file properties could store a script payload that executed in the browser of any visitor to a page displaying the block with the description or tags column enabled, including unauthenticated visitors. Successful exploitation could allow theft of session data or actions performed in the visitor's context. The block controller returned the description and tags values without the h() escaping already applied to the title column, and the block view template wrote the returned value directly into the results table The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N. Thanks Nguyen Manh Thuan for reporting.
Title Concrete CMS below 9.5.3 is vulnerable to Stored XSS in the Document Library block file description and tags
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-14T13:00:31.734Z

Reserved: 2026-08-27T18:23:01.365Z

Link: CVE-2026-81917

cve-icon Vulnrichment

Updated: 2026-09-14T12:57:39.903Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T21:17:20.747

Modified: 2026-09-18T15:18:54.377

Link: CVE-2026-81917

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')