Stored Cross-Site Scripting in Concrete CMS by Concrete5
CVE-2026-81899
7.3HIGH
What is CVE-2026-81899?
An issue within Concrete CMS allows unfiltered storage of group folder names, leading to stored cross-site scripting (XSS) vulnerabilities. The application's handling of these names in the Members > Groups dashboard lacks proper sanitization, enabling an authenticated user with permissions to add group folders to inject malicious scripts. When an administrator views the affected dashboard, the script executes within their session, creating potential for serious security breaches, including session and token theft. This outlines the necessity for robust input validation and output encoding in web applications.
Affected Version(s)
Concrete CMS 9.0.0 <= 9.5.2
