Description
Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data.
Published: 2026-09-18
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting allowing unauthenticated attackers to inject scripts that execute within authenticated manager sessions, facilitating rogue account creation or data exfiltration.
Action: Patch Now
AI Analysis

Impact

Concrete CMS Community Store versions prior to 2.7.8 render customer‑supplied billing fields without escaping, enabling stored XSS. An unauthenticated attacker can upload a script payload into the billing name, email, or phone fields during checkout or admin order view. When a manager logs in, the malicious script executes in the manager’s browser, allowing the attacker to create rogue accounts or exfiltrate sensitive data. The weakness is a classic stored XSS object (CWE‑79).

Affected Systems

Entities running Concrete CMS Community Store before version 2.7.8 are affected. The vulnerability applies to all installations using the community_store package, specifically those versions older than 2.7.8.

Risk and Exploitability

The CVSS score of 8.6 flags this issue as a critical vulnerability. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability, and the vulnerability is not currently listed in the CISA KEV catalog. Attackers can achieve it through an unauthenticated input vector, meaning any user with access to the checkout or order creation interfaces can submit a malicious payload. Because the payload is stored and later executed in a privileged context, the risk to integrity and confidentiality is high, and the exploitation likelihood can be considered significant given the high severity rating.

Generated by OpenCVE AI on September 28, 2026 at 16:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS Community Store to version 2.7.8 or later to receive the official patch which sanitizes all customer‑supplied billing fields.
  • If an upgrade is not immediately possible, implement a temporary input filter that removes potentially dangerous HTML and JavaScript from the billing fields before storing or displaying them.
  • Configure a strict Content Security Policy header that blocks inline scripts and unsafe eval in the manager interface to reduce the impact of any unintended script execution.

Generated by OpenCVE AI on September 28, 2026 at 16:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms-community-store
Concretecms-community-store community Store
Vendors & Products Concretecms-community-store
Concretecms-community-store community Store

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data.
Title Concrete CMS Community Store before 2.7.8 Stored XSS
First Time appeared Nbubna
Nbubna store
Weaknesses CWE-79
CPEs cpe:2.3:a:nbubna:store:*:*:*:*:*:*:*:*
Vendors & Products Nbubna
Nbubna store
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

Concretecms-community-store Community Store
Nbubna Store
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-28T15:19:53.808Z

Reserved: 2026-09-18T13:30:26.287Z

Link: CVE-2026-93659

cve-icon Vulnrichment

Updated: 2026-09-18T17:59:48.223Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T15:17:22.510

Modified: 2026-09-28T16:17:17.830

Link: CVE-2026-93659

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T16:30:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')