PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18113 Concrete CMS CVE debrief

A Cross-Site Scripting (XSS) vulnerability exists in Concrete CMS versions 9.0 to 9.5.2. An attacker who can create or rename pages could store a script through a child page name, which would execute in the browser of any visitor, editor, or administrator who views the navigation and opens the affected dropdown. The script executes with the victim's privileges, potentially allowing the attacker to read same-origin content or perform actions available to that user.

Vendor
Concrete CMS
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-20
Advisory published
2026-09-15
Advisory updated
2026-09-20

Who should care

Defenders responsible for Concrete CMS installations, particularly those with user-generated content or public-facing sites, should assess exposure and prioritize updates or compensating controls.

Why it matters

CVE-2026-18113 is a high-severity XSS vulnerability in Concrete CMS that allows attackers to execute scripts in the context of other users. Defenders should prioritize updates and monitoring to prevent exploitation.

  • Potential for attackers to read same-origin content
  • Potential for attackers to perform actions available to the victim user
  • Need for defenders to verify and update Concrete CMS installations
  • Possible impact on site integrity and user trust

Technical summary

The Top Navigation Bar block in Concrete CMS 9.0 to 9.5.2 does not HTML-escape dropdown child page names, allowing an attacker to store a script through a child page name. The script executes with the victim's privileges when a user views the navigation and opens the affected dropdown. This could allow the attacker to read same-origin content or perform actions available to that user. The vulnerability was given a CVSS v4.0 score of 7.5 by the Concrete CMS security team and reported by labixiaoxin97. Defenders should prioritize verifying and updating Concrete CMS installations to prevent exploitation.

Defensive priority

Defenders should prioritize verifying and updating Concrete CMS installations to prevent exploitation.

Recommended defensive actions

  • Verify Concrete CMS version and update to a fixed version if necessary
  • Restrict page creation and renaming privileges to trusted users
  • Monitor for suspicious activity on the Top Navigation Bar block
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability was reported by labixiaoxin97 and given a CVSS v4.0 score of 7.5 by the Concrete CMS security team. The NVD entry is currently Awaiting Analysis. Evidence is limited to the report and the CVSS score. Defenders should verify the report and assess exposure. The vulnerability affects Concrete CMS versions 9.0 to 9.5.2 and involves the Top Navigation Bar block not HTML-escaping dropdown child page names.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-18113 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-18113

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-18113 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18113

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes

    ff5b8ace-8b95-4078-9743-eac1ca5451de

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.