CVE-2026-81925
Analyzed Analyzed - Analysis Complete

Reflected XSS in Concrete CMS due to Unsanitized Custom Date Format

Vulnerability report for CVE-2026-81925, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-21

Assigner: ConcreteCMS

Description

Concrete CMS before 9.5.3 improperly neutralized a user-supplied custom date format when rendering conversation messages, resulting in reflected cross-site scripting. An attacker could execute arbitrary JavaScript in the browser of a user who was tricked into submitting a crafted POST request to the conversation view endpoint. Exploitation was aided by the absence of a CSRF token on the endpoint, which allowed the payload to be delivered through an auto-submitting cross-origin POST without authentication.Β The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-21
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
concretecms concrete_cms to 9.5.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Concrete CMS before 9.5.3 has a reflected cross-site scripting vulnerability due to improper neutralization of user-supplied custom date formats in conversation messages. This allows attackers to execute arbitrary JavaScript in a victim's browser by tricking them into submitting a crafted POST request to the conversation view endpoint.

Detection Guidance

This vulnerability involves reflected cross-site scripting in Concrete CMS due to improper neutralization of user-supplied custom date formats. Detection requires checking for outdated Concrete CMS versions (before 9.5.3) and reviewing server logs for suspicious POST requests to the conversation view endpoint without CSRF tokens.

Impact Analysis

An attacker could exploit this to run malicious scripts in your browser, potentially stealing session cookies, redirecting you to phishing sites, or performing actions on your behalf without your knowledge. The lack of a CSRF token means the attack can be delivered via an auto-submitting cross-origin POST without needing authentication.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR or HIPAA as it involves reflected cross-site scripting in Concrete CMS, which primarily affects user data integrity and confidentiality rather than regulatory controls. However, exploitation could lead to unauthorized access to user data, potentially violating GDPR's data protection principles or HIPAA's security requirements if sensitive data is compromised.

Mitigation Strategies

Immediately upgrade Concrete CMS to version 9.5.3 or later to address the vulnerability. Review and enforce CSRF token usage on all POST endpoints. Monitor network traffic for unusual POST requests to the conversation view endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81925. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart