PT-2026-92180 · Unknown · Concrete Cms

·

CVE-2026-81898

·

Published

2026-09-15

·

Updated

2026-09-20

CVSS v4.0

7.5

High

VectorAV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Concrete CMS versions prior to 9.5.3
Description Stored Cross-Site Scripting (XSS) is possible in Express association views due to the Address attribute's country-less text formatter skipping HTML-escaping. This occurs when a non-required Address attribute accepts a blank country and specific Express association templates, such as concrete/elements/express/form/view/dashboard/association.php, echo the association label mask without applying the h() function. A user capable of submitting an Address attribute can execute arbitrary scripts in the session of any dashboard user who views the affected entry.
Recommendations Update to version 9.5.3 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81898

Affected Products

Concrete Cms