Junglewise Threat Intelligence

CVE-2026-8203: Concrete CMS Stored XSS in height parameter

CVE-2026-8203 · Severity: high · CVSS 4 · Published 2026-05-21

Technologies: Concrete CMS, concrete5/concrete5 (Packagist). Vendors: Concrete CMS, Packagist.

Executive brief

Concrete CMS, a popular content management system, is vulnerable to a security flaw where malicious code can be stored within the system. An attacker with editor-level privileges can inject scripts that execute in the browsers of other users or visitors. This could allow an attacker to steal login sessions, capture sensitive user information, or perform unauthorized actions on behalf of other users.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in Concrete CMS versions 9.5.0 and earlier. The vulnerability is located in the controller responsible for handling the 'height' parameter, which fails to properly validate or sanitize input. An authenticated attacker with editor privileges can submit a malicious payload that is stored on the server. When other users, including administrators or site visitors, view the affected content, the malicious JavaScript executes in their browser context. This can lead to session hijacking (via cookie theft) or credential harvesting. The issue is addressed in version 9.5.1.

Affected products

  • Concrete CMS Concrete CMS <= 9.5.0

Timeline

  • 2026-05-21: disclosed
  • 2026-05-21: advisory
  • 2026-05-21: patched: Fixed in version 9.5.1

References

Related threats