CVE-2026-8139: Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName
Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updateCollectionAliasExternal bypasses being sanitized. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.0 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8139?
The severity of CVE-2026-8139 is rated low, with a CVSS score of 2.0.
What does CVE-2026-8139 affect?
CVE-2026-8139 affects Concrete CMS versions 9.5.0 and below, specifically concerning Stored XSS via the external-link page cvName.
How do I fix CVE-2026-8139?
To fix CVE-2026-8139, upgrade to a version of Concrete CMS later than 9.5.0 that contains a patch for this vulnerability.
What type of vulnerability is CVE-2026-8139?
CVE-2026-8139 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
What is the impact of CVE-2026-8139?
The impact of CVE-2026-8139 can allow attackers to execute malicious scripts in the context of users' browsers.