Description
Concrete CMS before 9.5.3 improperly neutralized a user-supplied custom date format when rendering conversation messages, resulting in reflected cross-site scripting. An attacker could execute arbitrary JavaScript in the browser of a user who was tricked into submitting a crafted POST request to the conversation view endpoint. Exploitation was aided by the absence of a CSRF token on the endpoint, which allowed the payload to be delivered through an auto-submitting cross-origin POST without authentication. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Published: 2026-09-15
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Upgrade
AI Analysis

Impact

Concrete CMS versions prior to 9.5.3 fail to neutralize a user‑supplied custom date format when rendering conversation messages, creating a reflected cross‑site scripting flaw that aligns with CWE‑79. The vulnerability allows malicious code execution in a victim’s browser after the user submits a crafted POST request to the conversation view endpoint, potentially compromising client‑side confidentiality, integrity, and availability for that user.

Affected Systems

Vendor: Concrete CMS. Product: Concrete CMS. Vulnerable editions include any releases before 9.5.3; any instance of Concrete CMS running those versions is at risk.

Risk and Exploitability

The CVSS v4.0 score of 2.1 indicates low overall severity, and the EPSS score of less than 1% shows a very low probability of exploitation in the wild. However, the vulnerability’s exploitation is aided by the lack of a CSRF token on the endpoint, enabling an attacker to deliver a payload via an auto‑submitting cross‑origin POST without authentication. The flaw is exposed on a publicly accessible endpoint, meaning that exploitation does not require prior authentication or privileged access, increasing the potential risk for exposed installations. The flaw is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 18, 2026 at 14:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to version 9.5.3 or later.
  • Modify the conversation view endpoint to enforce a CSRF token so that only legitimate, authenticated requests are processed.
  • Ensure that any user input for custom date formats is strictly sanitized or encoded before rendering to prevent script injection.

Generated by OpenCVE AI on September 18, 2026 at 14:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Concrete CMS before 9.5.3 improperly neutralized a user-supplied custom date format when rendering conversation messages, resulting in reflected cross-site scripting. An attacker could execute arbitrary JavaScript in the browser of a user who was tricked into submitting a crafted POST request to the conversation view endpoint. Exploitation was aided by the absence of a CSRF token on the endpoint, which allowed the payload to be delivered through an auto-submitting cross-origin POST without authentication. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Title Concrete CMS below 9.5.3 is vulnerable to Reflected Cross-Site Scripting (XSS) via Conversation Custom Date Format
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-16T17:48:00.821Z

Reserved: 2026-08-27T18:25:17.660Z

Link: CVE-2026-81925

cve-icon Vulnrichment

Updated: 2026-09-16T17:47:55.929Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:04.090

Modified: 2026-09-21T17:53:13.887

Link: CVE-2026-81925

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T14:30:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')