CVE-2026-18111: Concrete CMS below 9.5.4 allows privilege escalation because adding users and assigning groups do not require additional identity verification

Published Sep 15, 2026
·
Updated

Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image, and Image blocks and before Concrete 8.5.21 in the feature and Image blocks because the external link URL was insufficiently validated by the link filter and was rendered without output escaping. A user with page-editing permissions (such as Add Block combined with Edit Contents on a single page) could store a crafted external link value that broke out of the link markup and injected arbitrary JavaScript. The script executed in the browser session of any user who subsequently viewed, previewed, or edited the affected page, which could lead to session hijacking and escalation of privileges up to full administrative takeover. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 8.5 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks to KhanMarshai for reporting this issue.

Affected Software

3 affected components
Concrete CMS Concrete CMS<9.5.3
Concrete CMS Concrete CMS<8.5.21
Concrete CMS Concrete CMS<9.5.4

Event History

Sep 15, 2026
CVE Published
via MITRE·04:42 PM
Data Sourced
via MITRE·04:42 PM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments are affected according to the available version information?

The description identifies Concrete CMS 9 versions before 9.5.3 and Concrete CMS 8 versions before 8.5.21 as affected. The supplied title instead says below 9.5.4, so teams should reconcile that discrepancy with the referenced release information before determining remediation status.

2

What level of access does an attacker need?

An attacker needs page-editing permissions. The description gives Add Block combined with Edit Contents on a single page as an example of sufficient access.

3

Which content blocks can be used to trigger the issue?

In Concrete CMS 9, the affected blocks are Feature, Feature Link, Hero Image, and Image. In Concrete CMS 8, the description identifies the Feature and Image blocks.

4

Does exploitation require another user to interact with the affected page?

Yes. The injected script executes when another user views, previews, or edits the affected page, potentially allowing compromise of that user's session and privileges.

5

What is the potential impact if a privileged user visits a malicious page?

The stored script can hijack the visitor's browser session and escalate privileges. The described worst-case outcome is full administrative takeover.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203