CVE-2026-81911: Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot save_template via Unescaped Summary Description

Published Sep 11, 2026
·
Updated

Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot dialog. The customslot savetemplate endpoint authorizes the request only against the target board instance (canEditBoardContents()) and then persists the client-supplied selectedTemplateOption[collection] verbatim, rather than rebuilding the content object collection server-side and verifying that each item belongs to the authorized board's data pool. A user with permission to edit the contents of at least one board instance can therefore store a forged summary object whose description field carries a JavaScript-bearing HTML payload. The default summary template renders the description field without output encoding, so the payload executes in the browser of any user who views the affected board slot, including anonymous front-end visitors and dashboard users who preview the resulting rule or block. This can enable session or action takeover and escalation toward an administrator. Concrete CMS versions below 9 do not include the Boards feature and are not affected. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.8 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.

Affected Software

1 affected component
Concrete CMS Concrete CMS>=9.0.0<=9.5.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Concrete CMS to a version that resolves this vulnerability.

    Fixed in 9.5.2

Event History

Sep 11, 2026
CVE Published
via MITRE·07:24 PM
Data Sourced
via MITRE·07:24 PM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue, and who can be affected by the stored payload?

An attacker needs permission to edit the contents of at least one board instance. Once stored, the payload can execute for any user viewing the affected board slot, including anonymous front-end visitors and dashboard users previewing the related rule or block.

2

Are default deployments affected?

The default summary template renders the summary description without output encoding, so deployments using that template are affected when a malicious summary object is stored. Versions below 9 are not affected because they do not include the Boards feature.

3

What access does an attacker need to place the malicious content?

The attacker must be able to edit a board's contents, but the vulnerable save operation validates authorization only for the target board. It does not verify that the submitted collection item belongs to that board's authorized data pool.

4

How can administrators determine whether they may be exposed?

Check whether the site runs Concrete CMS 9.0.0 through 9.5.2 and uses Boards with board-content editors. Review board custom-slot summary descriptions and related previewed rules or blocks for unexpected HTML or JavaScript-bearing content.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203