Stored XSS Vulnerability in Concrete CMS by Concrete5
CVE-2026-18117
7.3HIGH
What is CVE-2026-18117?
Concrete CMS versions 9.0.0 through 9.5.3 are susceptible to stored XSS through the 'custom page alias name' feature. The flaw arises because the Edit Alias dialog only applies the trim() function to the user input without adequate input sanitization, allowing an attacker with editor permissions to craft a malicious alias name. This alias could then be rendered without escaping in the administrative Sitemap panel, subsequently executing the payload when administrators or editors access the panel. This vulnerability may lead to privilege escalation exploits through compromised active sessions.
Affected Version(s)
Concrete CMS 9.0.0 <= 9.5.2
