PT-2026-91752 · Unknown · Concrete Cms

·

CVE-2026-81900

·

Published

2026-09-14

·

Updated

2026-09-15

CVSS v4.0

7.3

High

VectorAV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Concrete CMS versions prior to 9.5.3
Description Stored cross-site scripting occurs because the YouTube block only applies the trim() function to stored width and height values. These values are then printed into iframe HTML attributes without escaping or integer casting. A user with edit block permission can inject an event handler that executes scripts for visitors viewing the page. If the visitor has administrative privileges, the script executes with those privileges.
Recommendations Update Concrete CMS to version 9.5.3 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81900

Affected Products

Concrete Cms