CVE-2026-81903
Undergoing Analysis Undergoing Analysis - In Progress

Stored XSS in Concrete CMS Page Containers

Vulnerability report for CVE-2026-81903, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-18

Assigner: ConcreteCMS

Description

Concrete CMS versions 9.0.0 to 9.5.2 stored the Page Container icon value submitted through the dashboard without validating it against the set of known container icons. The unvalidated value was later concatenated into the src attribute of an img tag by a helper that did not encode attribute output, and was rendered raw in the Containers dashboard list and editor views. A user with delegated access to the Page Containers dashboard could store a crafted icon value that broke out of the src attribute and executed script in the authenticated session of another editor or administrator who viewed the list, enabling session token theft and privileged dashboard actions.Β The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.0 with vector CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Andrew Gonzalez for reporting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-18
Generated
2026-10-05
AI Q&A
2026-09-15
EPSS Evaluated
2026-10-03
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
concretecms concrete_cms From 9.0.0 (inc) to 9.5.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Concrete CMS versions 9.0.0 to 9.5.2 had a flaw where the Page Container icon value was stored without validation. This unvalidated value was later used in an img tag's src attribute without proper encoding. A user with dashboard access could inject a crafted value to execute malicious scripts when another user viewed the list or editor, leading to session hijacking or unauthorized actions.

Detection Guidance

This vulnerability requires checking Concrete CMS installations for versions 9.0.0 to 9.5.2 and inspecting Page Container icon values for improper input handling. Review dashboard logs for suspicious icon values and test if raw JavaScript can be injected via the icon field. No specific commands are provided in the context.

Impact Analysis

If you use Concrete CMS versions 9.0.0 to 9.5.2, an attacker with delegated dashboard access could steal your session token or perform privileged actions by tricking you into viewing a malicious Page Container icon. This could allow them to impersonate you or gain administrative control over your site.

Compliance Impact

This vulnerability could potentially violate compliance with GDPR and HIPAA by enabling session token theft and unauthorized privileged actions. A user with delegated access could exploit this to gain unauthorized access to sensitive data, which may lead to data breaches. This could result in non-compliance with data protection requirements under GDPR and HIPAA, depending on the specific context of use.

Mitigation Strategies

Update Concrete CMS to version 9.5.3 or later to address the unvalidated Page Container icon issue. Review and restrict access to the Page Containers dashboard to trusted users only. Monitor dashboard activity for suspicious changes to container icons.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81903. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart