Stored XSS Vulnerability in Concrete CMS Versions 9 to 9.4.2
CVE-2025-8573
2LOW
What is CVE-2025-8573?
Concrete CMS versions 9 through 9.4.2 are susceptible to a stored XSS vulnerability that can be exploited via the Home Folder on the Members Dashboard page. Malicious administrators can create harmful folders filled with XSS code, which can be triggered when users log in. This flaw highlights the importance of securing web applications against potential internal threats, emphasizing the need for strong access controls and auditing capabilities.
Affected Version(s)
Concrete CMS 9.0.0 < 9.4.3
