CVE-2026-3240
Concrete CMS below 9.4.8 is vulnerable to Stored XSS via Legacy form
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
In Concrete CMS below version 9.4.8, a user with permission to edit a page with element Legacy form can perform a stored XSS attack towards high-privilege accounts via the Question field. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 4.8 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N Thanks minhnn42, namdi and quanlna2 from VCSLab-Viettel Cyber Security for reporting.
| CWE | CWE-79 |
| Vendor | concrete cms |
| Product | concrete cms |
| Published | Mar 4, 2026 |
| Last Updated | Mar 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for concrete cms concrete cms
Be the first to know when new unknown vulnerabilities affecting concrete cms concrete cms are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Concrete CMS / Concrete CMS
5 < 9.4.8
References
Credits
minhnn42, namdi and quanlna2 from VCSLab-Viettel Cyber Security