Cross-Site Scripting Vulnerability in Concrete CMS by Concrete5
CVE-2026-81897

7.7HIGH

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-81897?

A vulnerability exists in Concrete CMS versions prior to 9.5.3 where the save_control action in the Express entities forms dashboard controller fails to properly validate the anti-CSRF token. This oversight allows an unauthenticated remote attacker to exploit this flaw by tricking an authenticated administrator into submitting a forged request. As a result, the attacker can inject malicious JavaScript into an Express form Text control. This compromised input, lacking proper output encoding, is later executed as persistent JavaScript when an administrator views the affected form entry, leading to potential data exfiltration and unauthorized interactions.

Affected Version(s)

Concrete CMS 5.0.0 <= 9.5.2

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tenzai
.