CVE-2026-18117
Analyzed Analyzed - Analysis Complete

Stored XSS in Concrete CMS via Custom Page Alias

Vulnerability report for CVE-2026-18117, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-29

Assigner: ConcreteCMS

Description

Concrete CMS 9.0.0 through 9.5.3 is vulnerable to stored XSS via the custom page alias name (customAliasName) because the Edit Alias dialog applied only trim() to the submitted value and performed no input neutralization. An authenticated user holding canWrite (editor) permission on a page could store a malicious alias name that was later rendered unescaped in the administrative Sitemap panel, where it executed automatically in any administrator or editor session that opened the panel, allowing an editor to escalate to administrator through the victim's active session.Β The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N. Thanks Nguyen Manh Thuan for reporting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-29
Generated
2026-10-05
AI Q&A
2026-09-15
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
concretecms concrete_cms From 9.0.0 (inc) to 9.5.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Concrete CMS versions 9.0.0 through 9.5.3 are vulnerable to stored Cross-Site Scripting (XSS) via the custom page alias name. The Edit Alias dialog only applied a trim function to the input without neutralizing malicious scripts. This allowed authenticated users with edit permissions to store a malicious alias that executes unescaped in the Sitemap panel for any administrator or editor who views it, enabling session hijacking or privilege escalation.

Detection Guidance

Check Concrete CMS versions 9.0.0 through 9.5.3 for stored XSS via custom page alias names. Inspect the Edit Alias dialog for improper input neutralization. Review Sitemap panel rendering for unescaped malicious alias names.

Impact Analysis

An attacker with editor permissions could inject malicious scripts into a page alias. When an administrator or editor views the Sitemap panel, the script executes automatically, potentially stealing session cookies, performing actions on behalf of the victim, or escalating the attacker's privileges to administrator level.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's integrity and confidentiality principles or HIPAA's security requirements. If exploited, it may result in data breaches, non-compliance penalties, and reputational damage due to compromised user sessions or data exposure.

Mitigation Strategies

Upgrade Concrete CMS to a version beyond 9.5.3. Apply input neutralization to customAliasName fields. Restrict write permissions to trusted users only. Monitor Sitemap panel for suspicious alias names.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18117. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart