PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18111 Concrete CMS CVE debrief

A stored cross-site scripting (XSS) vulnerability exists in Concrete CMS versions before 9.5.3 and 8.5.21. An authenticated user with page-editing permissions could inject arbitrary JavaScript, potentially leading to session hijacking and privilege escalation. This vulnerability has a CVSS v4.0 score of 8.5, indicating high severity. The vulnerability exists in the Feature, Feature Link, Hero Image, and Image blocks of Concrete CMS. Defenders should assess exposure, apply patches, and restrict page-editing permissions to trusted users.

Vendor
Concrete CMS
Product
Unknown
CVSS
HIGH 8.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-22
Advisory published
2026-09-15
Advisory updated
2026-09-22

Who should care

Concrete CMS administrators, users with page-editing permissions, security teams responsible for monitoring and patching vulnerabilities in content management systems, and operators of affected platforms should be aware of this vulnerability. They should assess exposure, apply patches, and restrict page-editing permissions to trusted users. Additionally, security teams should monitor for suspicious activity on affected pages and review compensatingcontrols

Why it matters

This stored XSS vulnerability in Concrete CMS requires immediate attention from administrators and security teams. An authenticated user with page-editing permissions could inject arbitrary JavaScript, potentially leading to session hijacking and privilege escalation. The vulnerability has a CVSS v4.0 score of 8.5, indicating high severity. Defenders should assess exposure, apply patches, and restrict page-editing permissions to trusted users.

  • Session hijacking and potential escalation of privileges to full administrative takeover
  • Injection of arbitrary JavaScript in the browser session of users who view, preview, or edit affected pages
  • Potential for lateral movement and exploitation of other vulnerabilities
  • Verification of patch application and vulnerability remediation

Technical summary

The vulnerability exists in the Feature, Feature Link, Hero Image, and Image blocks of Concrete CMS. An authenticated user with page-editing permissions could store a crafted external link value that breaks out of the link markup and injects arbitrary JavaScript. The script executes in the browser session of any user who subsequently views, previews, or edits the affected page. This could lead to session hijacking and potential escalation of privileges to full administrative takeover. The vulnerability has a CVSS v4.0 score of 8.5, indicating high severity.

Defensive priority

High priority for Concrete CMS administrators and users with page-editing permissions to assess exposure and apply patches.

Recommended defensive actions

  • Assess exposure by checking if the installed Concrete CMS version is vulnerable
  • Apply patches or updates to vulnerable versions
  • Restrict page-editing permissions to trusted users
  • Monitor for suspicious activity on affected pages
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The vulnerability was reported by KhanMarshai and assigned a CVSS v4.0 score of 8.5 by the Concrete CMS security team. The NVD entry is currently Undergoing Analysis. The vulnerability affects Concrete CMS versions before 9.5.3 and 8.5.21. KhanMarshai provided details on the vulnerability, which was verified through limited source-provided information.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-18111 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-18111

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-18111 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18111

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes

    ff5b8ace-8b95-4078-9743-eac1ca5451de

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.