Concrete CMS 9.5.3 之前的版本未在“区块设计”对话框中对自定义样式值进行清理,就直接通过 DOM 汇点(DOM sink)将其写入页面 CSS,从而允许发生存储型跨站脚本攻击(Stored XSS)。具有编辑器权限的用户可以在管理员的会话中执行脚本,进而提升权限。Concrete CMS 安全团队为该漏洞分配的 CVSS v4.0 得分为 7.0,向量表达式为:CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N。感谢 Ng
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 5.0.0 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18117 | 7.3 HIGH | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Custom Page Alias Name |
| CVE-2026-81901 | 7.2 HIGH | Concrete CMS 9.2.0 to 9.5.2 is vulnerable to stored XSS due to missing authorization in th |
| CVE-2026-81902 | 7.1 HIGH | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to CSRF on Orphan Block Cleanup |
| CVE-2026-81903 | 7.0 HIGH | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS via Page Container icon |
No comments yet