HIGH
Concretecms
CVE published 2026-09-14
CVE-2026-18117
A stored XSS vulnerability exists in Concrete CMS versions 9.0.0 through 9.5.3. An authenticated user with canWrite (editor) permission can store a malicious alias name that is later rendered unescaped in the administrative Sitemap panel, potentially leading to privilege escalation from editor to administrator. This issue allows an editor to execute arbitrary code in the context of an administrator's sess [truncated]