Stored XSS Vulnerability in Concrete CMS by Concrete5
CVE-2026-18117

7.3HIGH

Key Information:

Vendor
CVE Published:
14 September 2026

What is CVE-2026-18117?

Concrete CMS versions 9.0.0 through 9.5.3 are susceptible to stored XSS through the 'custom page alias name' feature. The flaw arises because the Edit Alias dialog only applies the trim() function to the user input without adequate input sanitization, allowing an attacker with editor permissions to craft a malicious alias name. This alias could then be rendered without escaping in the administrative Sitemap panel, subsequently executing the payload when administrators or editors access the panel. This vulnerability may lead to privilege escalation exploits through compromised active sessions.

Affected Version(s)

Concrete CMS 9.0.0 <= 9.5.2

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manhthuan
.