PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-68528 Concrete CMS CVE debrief

A stored cross-site scripting vulnerability exists in Concrete CMS RSS Displayer block versions below 9.5.3. An attacker controlling a title in a syndicated feed could execute script in the site origin for any visitor, including administrators, without an account on that site. The vulnerability allows for the execution of arbitrary script, potentially leading to unauthorized actions by attackers on behalf of administrators. This requires prompt defensive action to verify exposure and apply patches or workarounds.

Vendor
Concrete CMS
Product
Unknown
CVSS
MEDIUM 6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-11
Original CVE updated
2026-09-11
Advisory published
2026-09-11
Advisory updated
2026-09-11

Who should care

Defenders managing Concrete CMS installations, particularly those using the RSS Displayer block, should assess exposure and apply patches or workarounds. This includes verifying Concrete CMS versions, identifying systems using the RSS Displayer block, and prioritizing patching or workarounds for affected systems. Security teams should also review compensating controls and monitor for suspicious activity on affected systems.

Why it matters

A stored cross-site scripting vulnerability in Concrete CMS RSS Displayer block versions below 9.5.3 allows attackers to execute script in the site origin, impacting site security and requiring prompt defensive action.

  • Execution of arbitrary script in the site origin for any visitor
  • Potential for unauthorized actions by attackers on behalf of administrators
  • Need for verification of Concrete CMS versions and exposure
  • Prioritization of patching or workarounds for affected systems

Technical summary

The Concrete CMS RSS Displayer block below version 9.5.3 rendered remote feed item titles without HTML escaping, allowing an attacker to execute script in the site origin for any visitor. This vulnerability is a result of the lack of HTML escaping in the RSS Displayer block, which enables an attacker to inject malicious script into the site. The vulnerability requires an attacker to control a title in a syndicated feed, and the execution of script occurs in the site origin for any visitor, including administrators.

Defensive priority

Defenders should prioritize verifying exposure and applying patches or workarounds, focusing on systems using the RSS Displayer block.

Recommended defensive actions

  • Verify Concrete CMS versions and identify systems using the RSS Displayer block
  • Apply patches or workarounds to upgrade to version 9.5.3 or later
  • Monitor for suspicious activity on affected systems
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability was reported by riodrwn and assigned a CVSS v4.0 score of 6.0 by the Concrete CMS security team. The team verified the vulnerability and provided a CVSS vector of CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N. The evidence is based on the report and the CVSS score provided by the Concrete CMS security team.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-68528 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-68528

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-68528 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-68528

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes

    ff5b8ace-8b95-4078-9743-eac1ca5451de

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.