Stored XSS in Concrete CMS Affects Users via Date Format Field
CVE-2026-81918
4.8MEDIUM
What is CVE-2026-81918?
Concrete CMS versions earlier than 9.5.3 are susceptible to a Stored Cross-Site Scripting (XSS) vulnerability, allowing users with edit_page_contents permissions to embed malicious scripts. This occurs through the Date Format field within the Page Attribute Display block, potentially leading to script execution in the browsers of users visiting the affected pages. Proper validation and sanitization measures are crucial to prevent such vulnerabilities and safeguard user data.
Affected Version(s)
Concrete CMS 5.0.0 <= 9.5.2
