PT-2026-93847 · Concrete Cms+1 · Concrete Cms

·

CVE-2026-85386

·

Published

2026-09-16

·

Updated

2026-09-21

CVSS v4.0

7.3

High

VectorAV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Concrete CMS versions prior to 9.5.4
Description Insufficient sanitization of XML and XSLT documents uploaded via a public Form Block file-upload question allows an unauthenticated visitor to store a malicious XML document. Because plain XML uploads are validated only by file extension and served inline from the application origin, an attacker can include an xml-stylesheet processing instruction referencing a same-origin XSLT stylesheet. When a victim opens the file, the browser executes attacker-controlled JavaScript in the application origin, resulting in stored cross-site scripting (XSS). If the victim is an authenticated administrator, this can lead to unauthorized actions, such as the creation of new administrative users.
Recommendations Update to version 9.5.4 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85386

Affected Products

Concrete Cms