Stored XSS Vulnerability in Concrete CMS by Concrete5
CVE-2026-18111

8.5HIGH

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-18111?

Concrete CMS versions prior to 9.5.3 and 8.5.21 are susceptible to stored cross-site scripting vulnerabilities, particularly in the Feature, Feature Link, Hero Image, and Image blocks. This arises due to inadequate validation of external link URLs in the link filter, allowing attackers to inject malicious JavaScript. A user with editing permissions can exploit this by inserting a crafted external link, which, when viewed by other users, executes the script within their browser sessions. This could potentially lead to session hijacking and privilege escalation, enabling attackers to gain full administrative access to the affected site.

Affected Version(s)

Concrete CMS 9.0.0 <= 9.5.2

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

khanmarshai
.