Stored Script Payload Risk in Concrete CMS Workflow Notifications
CVE-2026-18116
7.3HIGH
What is CVE-2026-18116?
Concrete CMS versions 8.3.0 to 9.5.2 are susceptible to a stored cross-site scripting vulnerability due to inadequate sanitization of calendar event names. Specifically, event names can include malicious script payloads that execute in the context of an administrator's browser when displaying workflow approval notifications in the 'Waiting For Me' dashboard block. This could allow an attacker, who is a registered user authorized to add events, to potentially exploit this weakness to create new administrative accounts, posing serious security risks to applications utilizing these versions.
Affected Version(s)
Concrete CMS 8.3.0 <= 9.5.2
