Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Yyyat

#45399of 57,584
6.5Total CVSS
Vulnerabilities · 1
PT-2026-93112
6.5
2026-09-15
Unknown · Concrete Cms · CVE-2026-18426
**Name of the Vulnerable Software and Affected Versions** Concrete CMS versions 9.0.0 through 9.5.2 **Description** An issue exists where block-level edit-permission checks are not enforced on the Express Form block's control-management actions. The system relies exclusively on CSRF (Cross-Site Request Forgery) token validation, but since the token is bound to the user and action rather than a specific block, page, or form, it can be reused. An authenticated user with edit access to one Express Form can use a valid token to add, modify, or delete controls on other Express Forms they are not authorized to edit. This can lead to stored XSS (Cross-Site Scripting), where a malicious script is permanently stored on the server and executed in the browser of other users, by injecting a control whose value is rendered as HTML. **Recommendations** Update Concrete CMS to a version later than 9.5.2.