PT-2026-93846 · Concrete Cms+1 · Concrete Cms

·

CVE-2026-85385

·

Published

2026-09-16

·

Updated

2026-09-21

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Concrete CMS versions prior to 9.5.4
Description Stored cross-site scripting occurs because the software fails to validate the uTimezone value during write operations and renders it without output encoding on the Dashboard user management page. This happens when the Date::getTimezoneDisplayName() function returns any non-IANA value unchanged. An attacker can save a malicious payload in this field, which then executes in an administrator's browser session when the affected user is viewed. This could allow the attacker to read CSRF tokens, create administrator accounts, or modify site settings. In version 9.5.3, this field is accessible to unauthenticated visitors via public registration, while in versions prior to 9.5.3, it is accessible to any authenticated user through the account profile editor. Exploitation requires the concrete.misc.user timezones setting to be enabled, and the unauthenticated path further requires public registration to be enabled.
Recommendations Update Concrete CMS to version 9.5.4 or later. Disable the concrete.misc.user timezones setting to prevent exploitation. Disable public registration to mitigate the risk for unauthenticated access.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85385

Affected Products

Concrete Cms