Stored DOM-based Cross-site Scripting in Concrete CMS by Vendor Concrete
CVE-2026-81894

8.5HIGH

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-81894?

Stored DOM-based Cross-site Scripting (XSS) exists in Concrete CMS versions 9.5.2 and below due to improper handling of captions in the Gallery block. The vulnerability is triggered when a user with editing permissions stores a caption that includes code, which is later executed in the browser of anyone accessing the lightbox for that image. This is caused by the bundled Magnific Popup lightbox script, which incorrectly re-parses the caption as HTML instead of treating it as plain text. This issue can lead to potential exploitation and compromise the security of websites utilizing Concrete CMS.

Affected Version(s)

Concrete CMS 5.0.0 <= 9.5.2

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tenzai
.