Cross-Site Scripting Vulnerability in Concrete CMS by Concrete5
CVE-2026-81900
7.3HIGH
What is CVE-2026-81900?
A security flaw in Concrete CMS versions prior to 9.5.3 could allow users with edit_block permission to inject malicious JavaScript code into the YouTube block. This vulnerability arises from the improper sanitization of width and height values, which are rendered directly in iframe HTML attributes. Consequently, this could lead to stored cross-site scripting (XSS) attacks, enabling an attacker to execute scripts with administrative privileges on pages viewed by other users. This emphasizes the importance of proper input validation and escaping mechanisms to prevent such potential exploitation.
Affected Version(s)
Concrete CMS 5.0.0 <= 9.5.2
