Stored DOM-based Cross-site Scripting in Concrete CMS by Vendor Concrete
CVE-2026-81894
8.5HIGH
What is CVE-2026-81894?
Stored DOM-based Cross-site Scripting (XSS) exists in Concrete CMS versions 9.5.2 and below due to improper handling of captions in the Gallery block. The vulnerability is triggered when a user with editing permissions stores a caption that includes code, which is later executed in the browser of anyone accessing the lightbox for that image. This is caused by the bundled Magnific Popup lightbox script, which incorrectly re-parses the caption as HTML instead of treating it as plain text. This issue can lead to potential exploitation and compromise the security of websites utilizing Concrete CMS.
Affected Version(s)
Concrete CMS 5.0.0 <= 9.5.2
