Cross-Site Scripting in Concrete CMS Document Library Block
CVE-2026-81917
5.1MEDIUM
What is CVE-2026-81917?
Concrete CMS versions prior to 9.5.3 contain a cross-site scripting vulnerability in the Document Library block. This issue arises from insufficient HTML output escaping of the file description and tags fields, allowing malicious users with file editing permissions to inject a script payload. When displayed on a webpage, this could execute in the browsers of all visitors, including those without authentication. The lack of proper escaping means that users could potentially steal session data, gaining unauthorized access or permissions. It's crucial for users of the affected Concrete CMS versions to update to the latest version to mitigate this risk.
Affected Version(s)
Concrete CMS 5.0.0 <= 9.5.2
