Reflected XSS in Concrete CMS Legacy Pagination Affects Administrators and Report Viewers
CVE-2026-8245
What is CVE-2026-8245?
Concrete CMS versions 9.5.0 and below are susceptible to a reflected XSS vulnerability in the Legacy Pagination feature. This issue arises when the application constructs pagination links by directly embedding user-controlled input into HTML attributes without proper sanitization. As a result, an authenticated user, such as an admin or report viewer, can be exploited through a crafted URL. If they navigate to a specifically designed page within the dashboard, malicious scripts can execute in their session, potentially compromising their account and sensitive information. The Concrete CMS team has documented this risk, and it is strongly recommended to update to the latest version to mitigate any potential exploitation.
Affected Version(s)
Concrete CMS 5.0 <= 9.5.0
