Stored XSS Vulnerability in Concrete CMS Affects User Security
CVE-2026-8203

7.3HIGH

Key Information:

Vendor
CVE Published:
21 May 2026

What is CVE-2026-8203?

Concrete CMS versions 9.5.0 and earlier are susceptible to a Stored XSS vulnerability through the unvalidated height parameter. When exploited, an attacker with editor privileges can inject malicious JavaScript into the application's interface. This can execute in the browser of unsuspecting visitors, potentially leading to session hijacking, credential theft, and a multitude of other harmful actions. Users of affected versions are urged to apply updates and confirm the security measures to protect their websites from such attacks.

Affected Version(s)

Concrete CMS 5 <= 9.5.0

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alfin Joseph
.