Stored Cross-Site Scripting in Concrete CMS by Concrete5
CVE-2026-18119
7HIGH
What is CVE-2026-18119?
This vulnerability affects Concrete CMS versions prior to 9.5.3, where improper sanitization of custom style values within the Block Design dialog enables stored cross-site scripting. An editor-level user could leverage this flaw to inject malicious scripts into the page CSS, potentially executing code in the context of an administrator's session and escalating their privileges. Properly addressing this vulnerability is essential for maintaining the security integrity of web applications using Concrete CMS.
Affected Version(s)
Concrete CMS 5.0.0 <= 9.5.2
