CVE-2026-81898
- EPSS 0.23%
- Veröffentlicht 15.09.2026 17:29:31
- Zuletzt bearbeitet 20.09.2026 01:16:30
In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stored XSS in Express association views. A user able to submit an Address attribute could execute script in the session of any da...
CVE-2026-81897
- EPSS 0.19%
- Veröffentlicht 15.09.2026 16:47:02
- Zuletzt bearbeitet 22.09.2026 19:16:52
In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not validate the anti-CSRF token. By causing an authenticated administrator to submit a forged cross-site request, a remote attacker witho...
CVE-2026-81896
- EPSS 0.25%
- Veröffentlicht 15.09.2026 16:44:40
- Zuletzt bearbeitet 22.09.2026 19:16:52
Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Form block question labels when rendering them as column headers in the Dashboard Form Submissions report (concrete/single_pages/dashboard/reports/forms/legacy.php). a rogu...
CVE-2026-18111
- EPSS 0.3%
- Veröffentlicht 15.09.2026 16:42:37
- Zuletzt bearbeitet 22.09.2026 19:16:42
Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image, and Image blocks and before Concrete 8.5.21 in the feature and Image blocks because the external link URL was insufficiently val...
CVE-2026-81895
- EPSS 0.23%
- Veröffentlicht 15.09.2026 16:39:04
- Zuletzt bearbeitet 22.09.2026 19:16:52
In Concrete CMS before 9.5.3, the Document Library block stored the file-set identifiers submitted through fsID[] without validating them as integers, and when the block was configured with setMode set to any it concatenated each stored identifier di...
CVE-2026-81894
- EPSS 0.25%
- Veröffentlicht 15.09.2026 16:35:37
- Zuletzt bearbeitet 22.09.2026 19:16:52
Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-image Caption field because the bundled Magnific Popup lightbox script (concrete/js/features/imagery/frontend.js) re-parses the attr...
CVE-2026-18110
- EPSS 0.25%
- Veröffentlicht 15.09.2026 16:33:36
- Zuletzt bearbeitet 22.09.2026 18:17:11
Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint (/ccm/system/user/autocomplete), which backs the "Preview as User" panel and other user-selector components. The endpoint validate...
CVE-2026-81900
- EPSS 0.25%
- Veröffentlicht 14.09.2026 22:07:58
- Zuletzt bearbeitet 16.09.2026 20:47:10
Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them into iframe HTML attributes without escaping or integer casting, resulting in stored cross-site scripting. A user with edit_block per...
CVE-2026-18116
- EPSS 0.25%
- Veröffentlicht 14.09.2026 22:05:49
- Zuletzt bearbeitet 21.09.2026 17:49:50
Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in the workflow approval and deletion notifications shown in the dashboard "Waiting For Me" block. A registered user permitted to add...
CVE-2026-18117
- EPSS 0.27%
- Veröffentlicht 14.09.2026 21:27:57
- Zuletzt bearbeitet 29.09.2026 19:17:27
Concrete CMS 9.0.0 through 9.5.3 is vulnerable to stored XSS via the custom page alias name (customAliasName) because the Edit Alias dialog applied only trim() to the submitted value and performed no input neutralization. An authenticated user holdin...