Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-85385— Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone Field

Quick assessment

Affected
Concrete CMS Concrete CMS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Concrete CMS 9.5.4 之前的版本在写入时未对用户时区值( )进行验证,并且在仪表板(Dashboard)的用户管理页面上未对其输出进行编码即直接渲染。在此场景下, 方法会原样返回任何非 IANA 标准的时区值。攻击者可将存储型跨站脚本(Stored XSS)载荷写入该字段,当管理员在仪表板中查看受影响的该用户时,恶意脚本将在管理员的浏览器中执行,从而在管理员会话中运行脚本(例如:读取 CSRF 令牌、创建管理员账户或修改站点设置)。 在 Concrete CMS 9.5.3 中,由于启用了公共注册功

CVSS 7.7 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85385

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone Field
Source: CVE Program / CVE List V5
Vulnerability Description
Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output encoding on the Dashboard user management page, where Date::getTimezoneDisplayName() returns any non-IANA value unchanged. A stored cross-site scripting payload saved in this field executed in an administrator's browser when they viewed the affected user in the Dashboard, running script in the admin session (for example to read CSRF tokens, create administrator accounts, or change site settings). In Concrete CMS 9.5.3 the field became reachable by unauthenticated visitors through public registration; in Concrete CMS below 9.5.3, the same field was reachable by any authenticated user through the account profile editor. Exploitation required concrete.misc.user_timezones to be enabled (off by default), and the unauthenticated path additionally required public registration to be enabled. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.7 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Suraj Bhosale for reporting.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Concrete CMS Concrete CMS 5.0.0 ~ 9.5.3 -

II. Public POCs for CVE-2026-85385

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85385

登录查看更多情报信息。

Other References for CVE-2026-85385 (1)

Same Patch Batch · Concrete CMS · 2026-09-16 · 6 CVEs total

CVE-2026-85386 7.3 HIGH Concrete CMS before 9.5.4 stored is vulneratble to cross-site scripting via unauthenticate
CVE-2026-18120 6.3 MEDIUM Missing Authorization in legacy Express entries search endpoint allows disclosure of Expre
CVE-2026-87028 5.3 MEDIUM Cross-Board IDOR in the Board Custom Slot Preview in Concrete CMS 9.0.0 through 9.5.3 Disc
CVE-2026-87031 2.1 LOW Missing authorization in the REST API user creation endpoint in Concrete CMS 9.2.0 through
CVE-2026-85387 2.0 LOW Concrete CMS before 9.5.4 allows a deactivated user to retain OAuth-authenticated REST API

IV. Related Vulnerabilities

V. Comments for CVE-2026-85385

No comments yet


Leave a comment