Reflected XSS in Concrete CMS Legacy Pagination Affects Administrators and Report Viewers
CVE-2026-8245

6MEDIUM

Key Information:

Vendor
CVE Published:
21 May 2026

What is CVE-2026-8245?

Concrete CMS versions 9.5.0 and below are susceptible to a reflected XSS vulnerability in the Legacy Pagination feature. This issue arises when the application constructs pagination links by directly embedding user-controlled input into HTML attributes without proper sanitization. As a result, an authenticated user, such as an admin or report viewer, can be exploited through a crafted URL. If they navigate to a specifically designed page within the dashboard, malicious scripts can execute in their session, potentially compromising their account and sensitive information. The Concrete CMS team has documented this risk, and it is strongly recommended to update to the latest version to mitigate any potential exploitation.

Affected Version(s)

Concrete CMS 5.0 <= 9.5.0

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yonatan Drori (Tenzai)
.