Concrete CMS 8.3.0 至 9.5.2 版本中,日历事件名称在存储时未进行净化处理,且在仪表盘的“待我处理”(Waiting For Me)区块中展示工作流审批和删除通知时,未对事件名称进行 HTML 转义。 任何被授权向受审批工作流管控的日历添加事件的注册用户,都可以提交一个事件名称中包含脚本载荷的事件。当该待处理请求在管理员的浏览器中显示时,该脚本会被执行,攻击者可借此创建一个新的管理员账户。 Concrete CMS 安全团队为此漏洞赋予的 CVSS v4.0 评分为 7.3,向量值为: CVS
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 8.3.0 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18117 | 7.3 HIGH | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Custom Page Alias Name |
| CVE-2026-81900 | 7.3 HIGH | Concrete CMS before 9.5.3 is vulnerable to Stored XSS in the YouTube block (vWidth/vHeight |
| CVE-2026-81901 | 7.2 HIGH | Concrete CMS 9.2.0 to 9.5.2 is vulnerable to stored XSS due to missing authorization in th |
| CVE-2026-81902 | 7.1 HIGH | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to CSRF on Orphan Block Cleanup |
| CVE-2026-18119 | 7.0 HIGH | Concrete CMS below 9.5.3 is vulnerable to Stored XSS via unsanitized inline block custom s |
| CVE-2026-81903 | 7.0 HIGH | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS via Page Container icon |
No comments yet