Stored Cross-Site Scripting in Concrete CMS by Concrete5
CVE-2026-81899

7.3HIGH

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-81899?

An issue within Concrete CMS allows unfiltered storage of group folder names, leading to stored cross-site scripting (XSS) vulnerabilities. The application's handling of these names in the Members > Groups dashboard lacks proper sanitization, enabling an authenticated user with permissions to add group folders to inject malicious scripts. When an administrator views the affected dashboard, the script executes within their session, creating potential for serious security breaches, including session and token theft. This outlines the necessity for robust input validation and output encoding in web applications.

Affected Version(s)

Concrete CMS 9.0.0 <= 9.5.2

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hunglyvn
.