Cross-Site Scripting in Concrete CMS Document Library Block
CVE-2026-81917

5.1MEDIUM

Key Information:

Vendor
CVE Published:
11 September 2026

What is CVE-2026-81917?

Concrete CMS versions prior to 9.5.3 contain a cross-site scripting vulnerability in the Document Library block. This issue arises from insufficient HTML output escaping of the file description and tags fields, allowing malicious users with file editing permissions to inject a script payload. When displayed on a webpage, this could execute in the browsers of all visitors, including those without authentication. The lack of proper escaping means that users could potentially steal session data, gaining unauthorized access or permissions. It's crucial for users of the affected Concrete CMS versions to update to the latest version to mitigate this risk.

Affected Version(s)

Concrete CMS 5.0.0 <= 9.5.2

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manhthuan
.