SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-81911

MEDIUM · CVSS 5.8 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Concrete CMS versions 9.0.0 to 9.5.2 are vulnerable to a Stored XSS attack via the custom_slot save_template endpoint, allowing users with edit permissions to inject malicious JavaScript into board summaries. This vulnerability can lead to session hijacking or unauthorized actions by executing the payload in the browsers of users who view the affected board, including anonymous visitors. Organizations using these versions of Concrete CMS should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-81911
Severity
MEDIUM
CVSS
5.8
EPSS
0.30%
Java

Original NVD Description

Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot dialog. The custom_slot save_template endpoint authorizes the request only against the target board instance (canEditBoardContents()) and then persists the client-supplied selectedTemplateOption[collection] verbatim, rather than rebuilding the content object collection server-side and verifying that each item belongs to the authorized board's data pool. A user with permission to edit the contents of at least one board instance can therefore store a forged summary object whose description field carries a JavaScript-bearing HTML payload. The default summary template renders the description field without output encoding, so the payload executes in the browser of any user who views the affected board slot, including anonymous front-end visitors and dashboard users who preview the resulting rule or block. This can enable session or action takeover and escalation toward an administrator. Concrete CMS versions below 9 do not include the Boards feature and are not affected. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.8 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.