Stored Cross-Site Scripting Vulnerability in Concrete CMS by Concrete Solutions
CVE-2026-85386

7.3HIGH

Key Information:

Vendor
CVE Published:
16 September 2026

What is CVE-2026-85386?

Concrete CMS versions before 9.5.4 contain a vulnerability that allows unauthenticated users to upload malicious XML documents via a public Form Block file-upload question. This issue arises due to improper sanitization of uploaded XML and XSLT files. When a user accesses the stored XML file directly, the embedded XSLT can execute JavaScript within the context of the Concrete CMS origin. If an authenticated administrator views the XML document, the malicious script can operate with elevated privileges, facilitating unauthorized actions such as the creation of new admin users.

Affected Version(s)

Concrete CMS 5.0.0 <= 9.5.3

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

koplo
.