Description
Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's duplicate-path confirmation dialog. The panel's check endpoint returned the submitted path unmodified in its JSON response, and client-side JavaScript inserted each value into the dialog as raw HTML, so a crafted page path executed script in the editor's authenticated browser session. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.0 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Published: 2026-09-15
Score: 2 Low
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (XSS) in authenticated editor sessions
Action: Assess Impact
AI Analysis

Impact

Based on the description, Concrete CMS 9.4.0 through 9.5.2 fails to escape page paths submitted through the duplicate‑path confirmation dialog, returning the raw path in a JSON response that client‑side JavaScript injects as raw HTML. This flaw enables an attacker to inject malicious script that executes within the editor’s authenticated browser context, leading to cross‑site scripting. The weakness is an instance of improper input validation, identified as CWE‑79.

Affected Systems

Concrete CMS versions 9.4.0 through 9.5.2 are affected. The issue originates in the location panel’s duplicate‑path confirmation dialog used by the editor component. Users with editor access who can create or modify page paths are the only ones attacking paths that can trigger the vulnerability.

Risk and Exploitability

The CVSS v4.0 score of 2.0 indicates a low severity, and the EPSS score of less than 1% suggests exploitation is unlikely in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is client‑side through the browser; an attacker must have an authenticated editor session and craft a malicious page path to trigger the execution. Because the attack impacts only the privileges of the authenticated user, the overall risk remains modest but should not be ignored.

Generated by OpenCVE AI on September 18, 2026 at 14:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to any release newer than 9.5.2 where the duplicate‑path dialog properly escapes page paths
  • Restrict editor feature access to trusted users until the patch is applied
  • Validate and sanitize page paths before sending them to the client, ensuring that HTML special characters are escaped

Generated by OpenCVE AI on September 18, 2026 at 14:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's duplicate-path confirmation dialog. The panel's check endpoint returned the submitted path unmodified in its JSON response, and client-side JavaScript inserted each value into the dialog as raw HTML, so a crafted page path executed script in the editor's authenticated browser session. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.0 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Title Concrete CMS 9.4.0 through 9.5.2 is vulnerable to Cross-site scripting in the location panel duplicate-path confirmation dialog
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-16T17:49:21.929Z

Reserved: 2026-08-27T18:25:34.983Z

Link: CVE-2026-81926

cve-icon Vulnrichment

Updated: 2026-09-16T17:49:13.509Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T21:16:43.067

Modified: 2026-09-21T17:53:00.563

Link: CVE-2026-81926

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T14:45:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')