Stored Cross-Site Scripting in Concrete CMS by Concrete5
CVE-2026-18119

7HIGH

Key Information:

Vendor
CVE Published:
14 September 2026

What is CVE-2026-18119?

This vulnerability affects Concrete CMS versions prior to 9.5.3, where improper sanitization of custom style values within the Block Design dialog enables stored cross-site scripting. An editor-level user could leverage this flaw to inject malicious scripts into the page CSS, potentially executing code in the context of an administrator's session and escalating their privileges. Properly addressing this vulnerability is essential for maintaining the security integrity of web applications using Concrete CMS.

Affected Version(s)

Concrete CMS 5.0.0 <= 9.5.2

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manhthuan
.