Stored Cross-Site Scripting Vulnerability in Concrete CMS
CVE-2026-3244
4.8MEDIUM
What is CVE-2026-3244?
In versions of Concrete CMS below 9.4.8, a stored cross-site scripting (XSS) vulnerability is present in the search block, where page names and content are not properly HTML encoded in the search results. This oversight enables authenticated attackers, specifically rogue administrators, to inject malicious JavaScript code via page names. When users search for and view these pages in the search results, the injected scripts can execute, potentially compromising user security and data integrity.
Affected Version(s)
Concrete CMS git 5 < 9.4.8
