Cross-Site Scripting Vulnerability in Concrete CMS by Concrete5
CVE-2026-18113
7.5HIGH
What is CVE-2026-18113?
In Concrete CMS versions 9.0 through 9.5.2, the Top Navigation Bar block is susceptible to cross-site scripting due to improper handling of dropdown child page names. This vulnerability allows an attacker with permissions to create or modify pages to inject malicious scripts via the names of child pages. When these page names are accessed by any user, including visitors and admins, the injected scripts execute in the context of the user's session, potentially granting the attacker access to sensitive information or enabling unauthorized actions within the application.
Affected Version(s)
Concrete CMS 9.0.0 <= 9.5.2
