Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-85386— Concrete CMS before 9.5.4 stored is vulneratble to cross-site scripting via unauthenticated XML/XSLT file upload in the Form Block

Quick assessment

Affected
Concrete CMS Concrete CMS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Concrete CMS 9.5.4 之前的版本未对通过公共表单块(Form Block)文件上传问题点上传的 XML 和 XSLT 文档进行有效消毒处理。纯 XML 文件上传仅基于文件扩展名进行验证,并被存储为可从应用程序自身源(origin)内联访问的公开文件。因此,未经身份验证的访客可以存储一个包含 处理指令的 XML 文档,该指令引用由攻击者提供的、同源(same-origin)的 XSLT 样式表。当受害者直接在浏览器中打开该存储的文件时,浏览器会获取该样式表,将文档转换为 HTML,并在 Concret

CVSS 7.3 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85386

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Concrete CMS before 9.5.4 stored is vulneratble to cross-site scripting via unauthenticated XML/XSLT file upload in the Form Block
Source: CVE Program / CVE List V5
Vulnerability Description
Concrete CMS before 9.5.4 did not sanitize XML and XSLT documents uploaded through a public Form Block file-upload question. Plain XML uploads were validated by file extension only and stored as publicly accessible files that were served inline from the application's own origin. An unauthenticated visitor could therefore store an XML document containing an xml-stylesheet processing instruction that referenced an attacker-supplied, same-origin XSLT stylesheet. When a victim opened the stored file directly in a browser, the browser fetched the stylesheet, transformed the document into HTML, and executed attacker-controlled JavaScript in the Concrete CMS origin (stored cross-site scripting). If the victim was an authenticated administrator, the script could act with that administrator's session, and the reporter demonstrated creation of a new user in the Administrators group. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Valentin SARRE (Independent security researcher) for reporting.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Concrete CMS Concrete CMS 5.0.0 ~ 9.5.3 -

II. Public POCs for CVE-2026-85386

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85386

登录查看更多情报信息。

Other References for CVE-2026-85386 (1)

Same Patch Batch · Concrete CMS · 2026-09-16 · 6 CVEs total

CVE-2026-85385 7.7 HIGH Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone Field
CVE-2026-18120 6.3 MEDIUM Missing Authorization in legacy Express entries search endpoint allows disclosure of Expre
CVE-2026-87028 5.3 MEDIUM Cross-Board IDOR in the Board Custom Slot Preview in Concrete CMS 9.0.0 through 9.5.3 Disc
CVE-2026-87031 2.1 LOW Missing authorization in the REST API user creation endpoint in Concrete CMS 9.2.0 through
CVE-2026-85387 2.0 LOW Concrete CMS before 9.5.4 allows a deactivated user to retain OAuth-authenticated REST API

IV. Related Vulnerabilities

V. Comments for CVE-2026-85386

No comments yet


Leave a comment