Stored XSS in Concrete CMS Address Attribute Allows Script Execution
CVE-2026-81898
7.5HIGH
What is CVE-2026-81898?
In versions of Concrete CMS prior to 9.5.3, a vulnerability in the Address attribute allows attackers to execute stored XSS attacks. By submitting an address with a blank country field, a malicious user can manipulate the database entry, leading to unescaped HTML content being displayed. This is particularly serious in Express association views, where it can result in scripts being executed in the sessions of dashboard users who access the affected entry. The vulnerability occurs due to improper HTML escaping in template files, specifically in association label masks. Prompt updates and security measures are recommended to prevent exploitation of this flaw.
Affected Version(s)
Concrete CMS 5.0.0 <= 9.5.2
