Description
Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block. A user with edit_page_contents permissions could store a payload which executes in the browser of any visitor who viewed a page where the block was configured to display a date-type attribute. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 4.8 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Oriol Ortiz for reporting.
Published: 2026-09-11
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS
Action: Immediate Patch
AI Analysis

Impact

This vulnerability allows a user who can edit page content to store malicious JavaScript in the Date Format field of the Page Attribute Display block. This is a Stored Cross‑Site Scripting flaw (CWE‑79). When a visitor views a page where the block is configured to display a date‑type attribute, the script executes in the visitor’s browser. The impact is client‑side code execution within the visitor’s browser, exposing them to potential damage limited to what the injected script can perform.

Affected Systems

Concrete CMS installations running any version earlier than 9.5.3 are affected. The issue is confined to the Page Attribute Display block and the date‑format configuration within that block.

Risk and Exploitability

The CVSS score is 4.8. The exploit requires the attacker to have edit_page_contents permissions, which are typically held by site editors or administrators. The vector AV:N indicates the attack can be performed over the network. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA KEV, implying no widespread, actively used exploit is known. Nevertheless, any user with edit_page_contents permissions can compromise all visitors to affected pages.

Generated by OpenCVE AI on September 15, 2026 at 20:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to version 9.5.3 or later.
  • If an upgrade is not possible immediately, remove or restrict the Page Attribute Display block usage, or restrict permissions to edit_page_contents to trusted users only.
  • Apply input validation and output escaping to the Date Format field, or use a content security policy that blocks inline scripts.

Generated by OpenCVE AI on September 15, 2026 at 20:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block. A user with edit_page_contents permissions could store a payload which executes in the browser of any visitor who viewed a page where the block was configured to display a date-type attribute. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 4.8 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Oriol Ortiz for reporting.
Title Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-14T13:00:31.576Z

Reserved: 2026-08-27T18:23:01.366Z

Link: CVE-2026-81918

cve-icon Vulnrichment

Updated: 2026-09-14T12:57:37.875Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T21:17:21.063

Modified: 2026-09-18T15:05:21.497

Link: CVE-2026-81918

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')