Cross-Site Scripting Vulnerability in Concrete CMS by Concrete5
CVE-2026-18113

7.5HIGH

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-18113?

In Concrete CMS versions 9.0 through 9.5.2, the Top Navigation Bar block is susceptible to cross-site scripting due to improper handling of dropdown child page names. This vulnerability allows an attacker with permissions to create or modify pages to inject malicious scripts via the names of child pages. When these page names are accessed by any user, including visitors and admins, the injected scripts execute in the context of the user's session, potentially granting the attacker access to sensitive information or enabling unauthorized actions within the application.

Affected Version(s)

Concrete CMS 9.0.0 <= 9.5.2

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

labixiaoxin97
.