Stored XSS Vulnerability in Concrete CMS RSS Displayer Block
CVE-2026-68528
6MEDIUM
What is CVE-2026-68528?
The Concrete CMS RSS Displayer block prior to version 9.5.3 exposes users to a stored cross-site scripting (XSS) vulnerability. This occurs because the block renders remote feed item titles without proper HTML escaping. An attacker who can control a title in a syndicated feed may inject malicious scripts that execute in the context of the site for any user visiting the affected page, including site administrators, without requiring an account. This vulnerability highlights the importance of validating and sanitizing input from external sources to safeguard against potential attacks.
Affected Version(s)
Concrete CMS 5.0.0 <= 9.5.2
