Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-81903— Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS via Page Container icon

Quick assessment

Affected
Concrete CMS Concrete CMS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Concrete CMS 版本 9.0.0 至 9.5.2 在通过仪表盘提交 Page Container 图标值时,未对该值进行针对已知容器图标集合的验证。该未经验证的值随后被一个未对属性输出进行编码的辅助函数拼接进 img 标签的 src 属性中,并在“容器”仪表盘列表视图和编辑器视图中以原始形式渲染。拥有 Page Containers 仪表盘委托访问权限的用户可以存储一个精心构造的图标值,该值能突破 src 属性边界,从而在查看列表的另一位编辑器或管理员的已认证会话中执行脚本,进而实现会话令牌窃取和特权仪表

CVSS 7.0 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81903

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS via Page Container icon
Source: CVE Program / CVE List V5
Vulnerability Description
Concrete CMS versions 9.0.0 to 9.5.2 stored the Page Container icon value submitted through the dashboard without validating it against the set of known container icons. The unvalidated value was later concatenated into the src attribute of an img tag by a helper that did not encode attribute output, and was rendered raw in the Containers dashboard list and editor views. A user with delegated access to the Page Containers dashboard could store a crafted icon value that broke out of the src attribute and executed script in the authenticated session of another editor or administrator who viewed the list, enabling session token theft and privileged dashboard actions. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.0 with vector CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Andrew Gonzalez for reporting.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Concrete CMS Concrete CMS 9.0.0 ~ 9.5.2 -

II. Public POCs for CVE-2026-81903

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81903

登录查看更多情报信息。

Vendor Pages for CVE-2026-81903 (1)

Same Patch Batch · Concrete CMS · 2026-09-14 · 7 CVEs total

CVE-2026-18117 7.3 HIGH Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Custom Page Alias Name
CVE-2026-81900 7.3 HIGH Concrete CMS before 9.5.3 is vulnerable to Stored XSS in the YouTube block (vWidth/vHeight
CVE-2026-18116 7.3 HIGH Concrete CMS 8.3.0 to 9.5.2 is vulnerable to Stored XSS in Calendar Event Name via Workflo
CVE-2026-81901 7.2 HIGH Concrete CMS 9.2.0 to 9.5.2 is vulnerable to stored XSS due to missing authorization in th
CVE-2026-81902 7.1 HIGH Concrete CMS 9.0.0 to 9.5.2 is vulnerable to CSRF on Orphan Block Cleanup
CVE-2026-18119 7.0 HIGH Concrete CMS below 9.5.3 is vulnerable to Stored XSS via unsanitized inline block custom s

IV. Related Vulnerabilities

V. Comments for CVE-2026-81903

No comments yet


Leave a comment