CVE-2026-81903
Received Received - Intake

Stored XSS in Concrete CMS Page Containers

Vulnerability report for CVE-2026-81903, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: ConcreteCMS

Description

Concrete CMS versions 9.0.0 to 9.5.2 stored the Page Container icon value submitted through the dashboard without validating it against the set of known container icons. The unvalidated value was later concatenated into the src attribute of an img tag by a helper that did not encode attribute output, and was rendered raw in the Containers dashboard list and editor views. A user with delegated access to the Page Containers dashboard could store a crafted icon value that broke out of the src attribute and executed script in the authenticated session of another editor or administrator who viewed the list, enabling session token theft and privileged dashboard actions.Β The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.0 with vector CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Andrew Gonzalez for reporting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
concrete_cms concrete_cms From 9.0.0 (inc) to 9.5.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Concrete CMS versions 9.0.0 to 9.5.2 had a flaw where the Page Container icon value was stored without validation. This unvalidated value was later used in an img tag's src attribute without proper encoding. A user with dashboard access could inject a crafted value to execute malicious scripts when another user viewed the list or editor, leading to session hijacking or unauthorized actions.

Impact Analysis

If you use Concrete CMS versions 9.0.0 to 9.5.2, an attacker with delegated dashboard access could steal your session token or perform privileged actions by tricking you into viewing a malicious Page Container icon. This could allow them to impersonate you or gain administrative control over your site.

Mitigation Strategies

Update Concrete CMS to version 9.5.3 or later to address the unvalidated Page Container icon issue. Review and restrict access to the Page Containers dashboard to trusted users only. Monitor dashboard activity for suspicious changes to container icons.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81903. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart