CVE-2026-68534
Received Received - Intake

Stored XSS in Concrete CMS Express Entry Labels

Vulnerability report for CVE-2026-68534, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: ConcreteCMS

Description

Concrete CMS before 9.5.3 rendered Express entry labels as raw HTML when displaying associated entries, resulting in stored cross-site scripting. An unauthenticated attacker could submit a payload through a public Express Form; it then executed in an administrator's dashboard session when the associated entry was viewed, or in the browser of any visitor to a page using an Express Entry List block with association columns, allowing actions to be performed with that user's privileges.Β The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks v01demort for reporting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
concrete_cms concrete_cms to 9.5.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Concrete CMS before version 9.5.3 had a stored cross-site scripting vulnerability where Express entry labels were rendered as raw HTML. This allowed an unauthenticated attacker to submit malicious payloads via a public Express Form. The payload would execute when viewed by an administrator in their dashboard or by visitors on pages using an Express Entry List block with association columns.

Detection Guidance

This vulnerability involves stored cross-site scripting in Concrete CMS versions before 9.5.3. To detect it, inspect Express entry labels for raw HTML payloads in the admin dashboard or pages using Express Entry List blocks. Check for unusual JavaScript execution in these areas.

Impact Analysis

An attacker could perform actions with the privileges of an administrator or other users by tricking them into viewing the malicious payload. This could lead to unauthorized data access, modifications, or other malicious activities within the affected system.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate compliance requirements such as GDPR or HIPAA. Organizations using vulnerable versions of Concrete CMS may face legal and regulatory penalties due to insufficient protection against cross-site scripting attacks.

Mitigation Strategies

Upgrade Concrete CMS to version 9.5.3 or later to patch the vulnerability. Review and sanitize all Express entry labels for malicious payloads. Monitor admin dashboard and public pages for unexpected script execution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68534. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart