Stored XSS Vulnerability in Concrete CMS RSS Displayer Block
CVE-2026-68528

6MEDIUM

Key Information:

Vendor
CVE Published:
11 September 2026

What is CVE-2026-68528?

The Concrete CMS RSS Displayer block prior to version 9.5.3 exposes users to a stored cross-site scripting (XSS) vulnerability. This occurs because the block renders remote feed item titles without proper HTML escaping. An attacker who can control a title in a syndicated feed may inject malicious scripts that execute in the context of the site for any user visiting the affected page, including site administrators, without requiring an account. This vulnerability highlights the importance of validating and sanitizing input from external sources to safeguard against potential attacks.

Affected Version(s)

Concrete CMS 5.0.0 <= 9.5.2

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

riodrwn
.