Concrete CMS 9.5.3 之前的版本仅对 YouTube 模块中存储的宽度和高度值应用了 操作,并将这些值直接打印到 iframe 的 HTML 属性中,而未进行转义或强制转换为整数,从而导致存储型跨站脚本(Stored XSS)漏洞。 拥有 权限的用户可以注入事件处理器,使得在渲染页面的访客执行脚本;当受害者是管理员时,该脚本将以管理员权限运行。 Concrete CMS 安全团队为该漏洞分配了 CVSS v4.0 分数 7.3,向量值为 。 感谢 sh4d0byss 报告此漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 5.0.0 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18117 | 7.3 HIGH | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Custom Page Alias Name |
| CVE-2026-18116 | 7.3 HIGH | Concrete CMS 8.3.0 to 9.5.2 is vulnerable to Stored XSS in Calendar Event Name via Workflo |
| CVE-2026-81901 | 7.2 HIGH | Concrete CMS 9.2.0 to 9.5.2 is vulnerable to stored XSS due to missing authorization in th |
| CVE-2026-81902 | 7.1 HIGH | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to CSRF on Orphan Block Cleanup |
| CVE-2026-18119 | 7.0 HIGH | Concrete CMS below 9.5.3 is vulnerable to Stored XSS via unsanitized inline block custom s |
| CVE-2026-81903 | 7.0 HIGH | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS via Page Container icon |
No comments yet