Concrete CMS 版本 9.0.0 至 9.5.2 在通过仪表盘提交 Page Container 图标值时,未对该值进行针对已知容器图标集合的验证。该未经验证的值随后被一个未对属性输出进行编码的辅助函数拼接进 img 标签的 src 属性中,并在“容器”仪表盘列表视图和编辑器视图中以原始形式渲染。拥有 Page Containers 仪表盘委托访问权限的用户可以存储一个精心构造的图标值,该值能突破 src 属性边界,从而在查看列表的另一位编辑器或管理员的已认证会话中执行脚本,进而实现会话令牌窃取和特权仪表
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 9.0.0 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18117 | 7.3 HIGH | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Custom Page Alias Name |
| CVE-2026-81900 | 7.3 HIGH | Concrete CMS before 9.5.3 is vulnerable to Stored XSS in the YouTube block (vWidth/vHeight |
| CVE-2026-18116 | 7.3 HIGH | Concrete CMS 8.3.0 to 9.5.2 is vulnerable to Stored XSS in Calendar Event Name via Workflo |
| CVE-2026-81901 | 7.2 HIGH | Concrete CMS 9.2.0 to 9.5.2 is vulnerable to stored XSS due to missing authorization in th |
| CVE-2026-81902 | 7.1 HIGH | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to CSRF on Orphan Block Cleanup |
| CVE-2026-18119 | 7.0 HIGH | Concrete CMS below 9.5.3 is vulnerable to Stored XSS via unsanitized inline block custom s |
No comments yet