Stored Cross-Site Scripting Vulnerability in Concrete CMS by Concrete Solutions
CVE-2026-85386
7.3HIGH
What is CVE-2026-85386?
Concrete CMS versions before 9.5.4 contain a vulnerability that allows unauthenticated users to upload malicious XML documents via a public Form Block file-upload question. This issue arises due to improper sanitization of uploaded XML and XSLT files. When a user accesses the stored XML file directly, the embedded XSLT can execute JavaScript within the context of the Concrete CMS origin. If an authenticated administrator views the XML document, the malicious script can operate with elevated privileges, facilitating unauthorized actions such as the creation of new admin users.
Affected Version(s)
Concrete CMS 5.0.0 <= 9.5.3
