Stored Script Payload Risk in Concrete CMS Workflow Notifications
CVE-2026-18116

7.3HIGH

Key Information:

Vendor
CVE Published:
14 September 2026

What is CVE-2026-18116?

Concrete CMS versions 8.3.0 to 9.5.2 are susceptible to a stored cross-site scripting vulnerability due to inadequate sanitization of calendar event names. Specifically, event names can include malicious script payloads that execute in the context of an administrator's browser when displaying workflow approval notifications in the 'Waiting For Me' dashboard block. This could allow an attacker, who is a registered user authorized to add events, to potentially exploit this weakness to create new administrative accounts, posing serious security risks to applications utilizing these versions.

Affected Version(s)

Concrete CMS 8.3.0 <= 9.5.2

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

v01demort
.