SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-81918

MEDIUM · CVSS 4.8 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Concrete CMS versions prior to 9.5.3 are susceptible to a Stored XSS vulnerability through the Date Format field in the Page Attribute Display block, allowing users with edit_page_contents permissions to inject malicious scripts. This could lead to the execution of the payload in the browsers of any visitors viewing the affected pages, potentially compromising user data and session integrity. Organizations using Concrete CMS should prioritize patching this vulnerability to mitigate risks associated with unauthorized script execution.

CVE
CVE-2026-81918
Severity
MEDIUM
CVSS
4.8
EPSS
0.30%

Original NVD Description

Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block. A user with edit_page_contents permissions could store a payload which executes in the browser of any visitor who viewed a page where the block was configured to display a date-type attribute. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 4.8 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Oriol Ortiz for reporting.