Stored XSS Vulnerability in Concrete CMS Affects User Security
CVE-2026-8203
7.3HIGH
What is CVE-2026-8203?
Concrete CMS versions 9.5.0 and earlier are susceptible to a Stored XSS vulnerability through the unvalidated height parameter. When exploited, an attacker with editor privileges can inject malicious JavaScript into the application's interface. This can execute in the browser of unsuspecting visitors, potentially leading to session hijacking, credential theft, and a multitude of other harmful actions. Users of affected versions are urged to apply updates and confirm the security measures to protect their websites from such attacks.
Affected Version(s)
Concrete CMS 5 <= 9.5.0
