Concrete Cms · Concrete Cms · CVE-2026-68534
**Name of the Vulnerable Software and Affected Versions**
Concrete CMS versions prior to 9.5.3
**Description**
Stored cross-site scripting occurs because Express entry labels are rendered as raw HTML when displaying associated entries. An unauthenticated attacker can submit a malicious payload through a public Express Form. This payload executes within an administrator's dashboard session when the associated entry is viewed, or in the browser of any visitor to a page utilizing an Express Entry List block with association columns, enabling actions to be performed with the privileges of that user.
**Recommendations**
Update Concrete CMS to version 9.5.3 or later.