CVE-2026-81927
Received Received - Intake

Stored XSS in Concrete CMS SVG File Handling

Vulnerability report for CVE-2026-81927, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-18

Assigner: ConcreteCMS

Description

Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling. When SVG processing was set to the non-default "Reject files containing potentially harmful elements" mode (concrete.file_manager.images.svg_sanitization.action = reject), uploaded SVGs were checked only against a small built-in blocklist covering the script element and on* event-handler attributes; the broader enshrined/svg-sanitize pass still ran, but its result was discarded, so vectors it would have stripped, such as a javascript: URI in an xlink:href, were stored unmodified and executed when the file was opened directly. A user able to upload files could thereby run arbitrary JavaScript in the browser of any user who viewed the file. The default sanitize mode was not affected.Β The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 1.8 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Oriol Ortiz for reporting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-18
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
concretecms concrete_cms to 9.5.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Concrete CMS before 9.5.3 had a stored cross-site scripting (XSS) vulnerability in SVG file handling. When SVG processing was set to a specific non-default mode, uploaded SVGs were only checked against a limited blocklist for script elements and event-handler attributes. Other harmful elements like javascript: URIs were not properly sanitized and could execute when the file was viewed.

Detection Guidance

Check Concrete CMS version with: grep -r "concrete.file_manager.images.svg_sanitization.action" /path/to/concrete/config. If set to 'reject', the vulnerability may exist. Inspect uploaded SVG files for malicious content like javascript: URIs in xlink:href attributes.

Impact Analysis

An attacker with upload privileges could embed malicious JavaScript in an SVG file. When another user views the file, the script executes in their browser, potentially stealing session cookies, redirecting to phishing sites, or performing actions on their behalf.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR, HIPAA, or similar standards. It involves stored cross-site scripting in SVG files, which could allow unauthorized script execution in user browsers. Compliance risks would arise only if such a vulnerability led to data breaches or unauthorized access, which is not described in the provided context.

Mitigation Strategies

Upgrade Concrete CMS to version 9.5.3 or later. Change SVG sanitization mode to 'sanitize' if currently set to 'reject'. Review and remove any suspicious SVG files uploaded by users.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81927. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart