Description
Concrete CMS before 9.5.4 did not sanitize XML and XSLT documents uploaded through a public Form Block file-upload question. Plain XML uploads were validated by file extension only and stored as publicly accessible files that were served inline from the application's own origin. An unauthenticated visitor could therefore store an XML document containing an xml-stylesheet processing instruction that referenced an attacker-supplied, same-origin XSLT stylesheet. When a victim opened the stored file directly in a browser, the browser fetched the stylesheet, transformed the document into HTML, and executed attacker-controlled JavaScript in the Concrete CMS origin (stored cross-site scripting). If the victim was an authenticated administrator, the script could act with that administrator's session, and the reporter demonstrated creation of a new user in the Administrators group. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Valentin SARRE (Independent security researcher) for reporting.
Published: 2026-09-16
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross‑site scripting that can execute code as a logged‑in administrator
Action: Patch immediately
AI Analysis

Impact

Concrete CMS versions prior to 9.5.4 allow an unauthenticated user to upload plain XML documents via a public Form Block file‑upload question. The system validates uploads only by file extension and serves them inline with the application’s origin. An attacker can embed an XML‑STYLESHEET instruction that points to a malicious XSLT resource on the same domain. When a victim opens the stored file, the browser applies the stylesheet, rendering attacker‑controlled JavaScript in the Concrete CMS context. If the victim is an authenticated administrator, the script runs with administrative privileges and can, for example, create new Administrator accounts. This is a stored XSS flaw that can compromise confidentiality, integrity, and availability for privileged users.

Affected Systems

Concrete CMS, all versions older than 9.5.4

Risk and Exploitability

The CVSS v4.0 score of 7.3 indicates moderate to high severity. The EPSS score of less than 1 % suggests low probability of widespread exploitation, and the vulnerability is not listed in CISA KEV. The attack does not require network privileges, relies on an unauthenticated upload to a publicly exposed Form Block, and then requires a victim to open the stored XML file in a browser. The flaw can be exploited by anyone with access to the Form Block, and malicious scripts will execute under the victim’s session.

Generated by OpenCVE AI on September 18, 2026 at 01:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to version 9.5.4 or later, which removes the unauthenticated XML/XSLT upload issue.
  • If an immediate upgrade is not possible, restrict or disable the Form Block’s file‑upload question for unauthenticated users, giving upload capability only to privileged accounts.
  • After applying an upgrade or restriction, delete all stored XML and XSLT files that had been uploaded to prevent the stored XSS vector from remaining in the system.

Generated by OpenCVE AI on September 18, 2026 at 01:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Fri, 18 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS before 9.5.4 did not sanitize XML and XSLT documents uploaded through a public Form Block file-upload question. Plain XML uploads were validated by file extension only and stored as publicly accessible files that were served inline from the application's own origin. An unauthenticated visitor could therefore store an XML document containing an xml-stylesheet processing instruction that referenced an attacker-supplied, same-origin XSLT stylesheet. When a victim opened the stored file directly in a browser, the browser fetched the stylesheet, transformed the document into HTML, and executed attacker-controlled JavaScript in the Concrete CMS origin (stored cross-site scripting). If the victim was an authenticated administrator, the script could act with that administrator's session, and the reporter demonstrated creation of a new user in the Administrators group. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Valentin SARRE (Independent security researcher) for reporting.
Title Concrete CMS before 9.5.4 stored is vulneratble to cross-site scripting via unauthenticated XML/XSLT file upload in the Form Block
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-17T17:34:33.004Z

Reserved: 2026-09-03T18:09:31.837Z

Link: CVE-2026-85386

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T17:18:15.710

Modified: 2026-09-21T17:51:55.300

Link: CVE-2026-85386

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:15:02Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')