PT-2026-93123 · Unknown · Concrete Cms

·

CVE-2026-81926

·

Published

2026-09-15

·

Updated

2026-09-21

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Concrete CMS versions 9.4.0 through 9.5.2
Description Concrete CMS fails to escape colliding page paths before rendering them in the location panel's duplicate-path confirmation dialog. The check endpoint returns the submitted path unmodified in its JSON response, and client-side JavaScript inserts this value into the dialog as raw HTML. This allows a crafted page path to execute scripts within the authenticated browser session of an editor.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81926

Affected Products

Concrete Cms