Cross-Site Scripting Vulnerability in Concrete CMS by Concrete5
CVE-2026-81897
7.7HIGH
What is CVE-2026-81897?
A vulnerability exists in Concrete CMS versions prior to 9.5.3 where the save_control action in the Express entities forms dashboard controller fails to properly validate the anti-CSRF token. This oversight allows an unauthenticated remote attacker to exploit this flaw by tricking an authenticated administrator into submitting a forged request. As a result, the attacker can inject malicious JavaScript into an Express form Text control. This compromised input, lacking proper output encoding, is later executed as persistent JavaScript when an administrator views the affected form entry, leading to potential data exfiltration and unauthorized interactions.
Affected Version(s)
Concrete CMS 5.0.0 <= 9.5.2
