Cross-Site Scripting Vulnerability in Concrete CMS by Concrete5
CVE-2026-81900

7.3HIGH

Key Information:

Vendor
CVE Published:
14 September 2026

What is CVE-2026-81900?

A security flaw in Concrete CMS versions prior to 9.5.3 could allow users with edit_block permission to inject malicious JavaScript code into the YouTube block. This vulnerability arises from the improper sanitization of width and height values, which are rendered directly in iframe HTML attributes. Consequently, this could lead to stored cross-site scripting (XSS) attacks, enabling an attacker to execute scripts with administrative privileges on pages viewed by other users. This emphasizes the importance of proper input validation and escaping mechanisms to prevent such potential exploitation.

Affected Version(s)

Concrete CMS 5.0.0 <= 9.5.2

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sh4d0byss
.