CVE-2026-18119: Concrete CMS below 9.5.3 is vulnerable to Stored XSS via unsanitized inline block custom style values
Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page CSS via a DOM sink, permitting stored cross-site scripting. An editor-level user could execute script in an administrator's session and escalate privileges. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.0 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Nguyen Manh Thuan for reporting.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue, and whose session is at risk?
An editor-level user can exploit the issue by supplying a malicious custom style value in the Block Design dialog. The stored script can execute in an administrator's session, enabling privilege escalation.
Which deployments are affected?
Concrete CMS versions below 9.5.3 are affected. The issue is specifically associated with custom style values for inline blocks written into page CSS.
What should teams do if they cannot upgrade immediately?
The provided information does not specify a workaround. As an interim risk-reduction measure supported by the attack prerequisites, restrict access to editor-level accounts and review use of custom style values in the Block Design dialog.