Stored XSS Vulnerability in Concrete CMS by Concrete5
CVE-2026-18111
8.5HIGH
What is CVE-2026-18111?
Concrete CMS versions prior to 9.5.3 and 8.5.21 are susceptible to stored cross-site scripting vulnerabilities, particularly in the Feature, Feature Link, Hero Image, and Image blocks. This arises due to inadequate validation of external link URLs in the link filter, allowing attackers to inject malicious JavaScript. A user with editing permissions can exploit this by inserting a crafted external link, which, when viewed by other users, executes the script within their browser sessions. This could potentially lead to session hijacking and privilege escalation, enabling attackers to gain full administrative access to the affected site.
Affected Version(s)
Concrete CMS 9.0.0 <= 9.5.2
