CVE-2026-68534
Concrete CMS below 9.5.2 is vulnerable to Stored XSS via unescaped Express entry labels in association selectors
Concrete CMS before 9.5.3 rendered Express entry labels as raw HTML when displaying associated entries, resulting in stored cross-site scripting. An unauthenticated attacker could submit a payload through a public Express Form; it then executed in an administrator's dashboard session when the associated entry was viewed, or in the browser of any visitor to a page using an Express Entry List block with association columns, allowing actions to be performed with that user's privileges.Β The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks v01demort for reporting.
| CWE | CWE-79 |
| Vendor | concrete cms |
| Product | concrete cms |
| Published | Sep 15, 2026 |
| Last Updated | Sep 15, 2026 |
Get instant alerts for concrete cms concrete cms
Be the first to know when new unknown vulnerabilities affecting concrete cms concrete cms are published β delivered to Slack, Telegram or Discord.