Concrete CMS 9.0.0 至 9.5.3 版本存在存储型 XSS 漏洞,该漏洞通过自定义页面别名(customAliasName)触发。原因在于“编辑别名”对话框仅对提交的值应用了 trim() 函数,而未进行任何输入中和处理。拥有页面 write(编辑器)权限的已认证用户,可以存储一个恶意的别名名称,该名称随后在管理后台的“站点地图”面板中被未转义地渲染出来,并在任何打开该面板的管理员或编辑会话中自动执行。这使得编辑器能够借助受害者的活跃会话,将其权限提升为管理员。Concrete CMS 安全团队为
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 9.0.0 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81900 | 7.3 HIGH | Concrete CMS before 9.5.3 is vulnerable to Stored XSS in the YouTube block (vWidth/vHeight |
| CVE-2026-18116 | 7.3 HIGH | Concrete CMS 8.3.0 to 9.5.2 is vulnerable to Stored XSS in Calendar Event Name via Workflo |
| CVE-2026-81901 | 7.2 HIGH | Concrete CMS 9.2.0 to 9.5.2 is vulnerable to stored XSS due to missing authorization in th |
| CVE-2026-81902 | 7.1 HIGH | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to CSRF on Orphan Block Cleanup |
| CVE-2026-18119 | 7.0 HIGH | Concrete CMS below 9.5.3 is vulnerable to Stored XSS via unsanitized inline block custom s |
| CVE-2026-81903 | 7.0 HIGH | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS via Page Container icon |
No comments yet