Stored XSS in Concrete CMS Address Attribute Allows Script Execution
CVE-2026-81898

7.5HIGH

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-81898?

In versions of Concrete CMS prior to 9.5.3, a vulnerability in the Address attribute allows attackers to execute stored XSS attacks. By submitting an address with a blank country field, a malicious user can manipulate the database entry, leading to unescaped HTML content being displayed. This is particularly serious in Express association views, where it can result in scripts being executed in the sessions of dashboard users who access the affected entry. The vulnerability occurs due to improper HTML escaping in template files, specifically in association label masks. Prompt updates and security measures are recommended to prevent exploitation of this flaw.

Affected Version(s)

Concrete CMS 5.0.0 <= 9.5.2

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tenzai
.