Description
Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling. When SVG processing was set to the non-default "Reject files containing potentially harmful elements" mode (concrete.file_manager.images.svg_sanitization.action = reject), uploaded SVGs were checked only against a small built-in blocklist covering the script element and on* event-handler attributes; the broader enshrined/svg-sanitize pass still ran, but its result was discarded, so vectors it would have stripped, such as a javascript: URI in an xlink:href, were stored unmodified and executed when the file was opened directly. A user able to upload files could thereby run arbitrary JavaScript in the browser of any user who viewed the file. The default sanitize mode was not affected. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 1.8 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Oriol Ortiz for reporting.
Published: 2026-09-15
Score: 1.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS that permits arbitrary JavaScript execution in the browsers of users who open a malicious SVG
Action: Patch
AI Analysis

Impact

Concrete CMS before version 9.5.3 contains a stored cross‑site scripting flaw that is triggered when SVG files are uploaded with the "Reject" sanitization mode enabled. In that mode the system checks only a limited blocklist that rejects the <script> element and on* event‑handler attributes, while discarding the more comprehensive sanitization pass that would normally strip dangerous content such as javascript: URIs in an xlink:href attribute. As a result, a malicious SVG containing executable JavaScript can be stored on the server and will run automatically when any user opens the file, allowing an attacker to run arbitrary code in the victim’s browser.

Affected Systems

The vulnerability affects Concrete CMS releases prior to 9.5.3 when the configuration parameter concrete.file_manager.images.svg_sanitization.action is set to "reject". The default sanitization mode is not impacted, and the flaw only applies if the reject mode is explicitly chosen. Users who have permission to upload SVG files are at risk until the patch or configuration change is applied.

Risk and Exploitability

The CVSS v4.0 score of 1.8 indicates low severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation in practice. The flaw requires that an attacker can upload SVG files in an environment where the reject mode is active, which limits the attack surface to users with upload privileges. Because the vulnerability is not listed in the CISA KEV catalog, the threat is confined to browser execution in users who view the malicious file and does not result in broader system compromise.

Generated by OpenCVE AI on September 18, 2026 at 14:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to version 9.5.3 or later to apply the corrected sanitization logic.
  • Change the concrete.file_manager.images.svg_sanitization.action setting to its default value or another safe mode so the vulnerable reject mode is not in use.
  • Restrict the ability to upload SVG files to trusted users only, or disable SVG uploads entirely until the patch is deployed.

Generated by OpenCVE AI on September 18, 2026 at 14:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling. When SVG processing was set to the non-default "Reject files containing potentially harmful elements" mode (concrete.file_manager.images.svg_sanitization.action = reject), uploaded SVGs were checked only against a small built-in blocklist covering the script element and on* event-handler attributes; the broader enshrined/svg-sanitize pass still ran, but its result was discarded, so vectors it would have stripped, such as a javascript: URI in an xlink:href, were stored unmodified and executed when the file was opened directly. A user able to upload files could thereby run arbitrary JavaScript in the browser of any user who viewed the file. The default sanitize mode was not affected. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 1.8 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Oriol Ortiz for reporting.
Title Concrete CMS before 9.5.3 is vulnerable to Stored XSS via SVG upload in "Reject" sanitization mode
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 1.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-16T17:52:45.158Z

Reserved: 2026-08-27T18:25:43.099Z

Link: CVE-2026-81927

cve-icon Vulnrichment

Updated: 2026-09-16T17:52:36.319Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T21:16:43.220

Modified: 2026-09-18T15:15:46.303

Link: CVE-2026-81927

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T14:30:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')