๐Ÿ” CVE Alert

CVE-2026-93659

HIGH 8.7

Concrete CMS Community Store before 2.7.8 Stored XSS

CVSS Score
8.7
EPSS Score
0.0%
EPSS Percentile
0th

Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data.

CWE CWE-79
Vendor concretecms-community-store
Product community_store
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for concretecms-community-store community_store

Be the first to know when new high vulnerabilities affecting concretecms-community-store community_store are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

concretecms-community-store / community_store
0 < 2.7.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/concretecms-community-store/community_store/commit/2a802d6a5717f4e351ef21fdf8bdaf8061c40109 github.com: https://github.com/concretecms-community-store/community_store/blob/v2.7.7/elements/order_slip.php github.com: https://github.com/concretecms-community-store/community_store/releases/tag/v2.7.8 github.com: https://github.com/concretecms-community-store/community_store vulncheck.com: https://www.vulncheck.com/advisories/concrete-cms-community-store-before-2.7.8-stored-xss

Credits

Prince Edem Fiagbedzi