Stored Cross-Site Scripting Vulnerability in Concrete CMS
CVE-2026-3244

4.8MEDIUM

Key Information:

Vendor
CVE Published:
4 March 2026

What is CVE-2026-3244?

In versions of Concrete CMS below 9.4.8, a stored cross-site scripting (XSS) vulnerability is present in the search block, where page names and content are not properly HTML encoded in the search results. This oversight enables authenticated attackers, specifically rogue administrators, to inject malicious JavaScript code via page names. When users search for and view these pages in the search results, the injected scripts can execute, potentially compromising user security and data integrity.

Affected Version(s)

Concrete CMS git 5 < 9.4.8

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zolpak
.