PT-2026-95428 · Concrete Cms · Community Store
CVE-2026-93659
·
Published
2026-09-18
·
Updated
2026-09-28
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Concrete CMS Community Store versions prior to 2.7.8
Description
The software fails to perform HTML escaping on customer-supplied order fields within checkout and admin views. This allows unauthenticated attackers to store malicious script payloads in the
billing name, email, or phone fields. These scripts execute during authenticated manager sessions, potentially leading to the creation of rogue accounts or the exfiltration of sensitive data.Recommendations
Update Concrete CMS Community Store to version 2.7.8 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Community Store