Junglewise Threat Intelligence

CVE-2026-8353: Concrete CMS Stored XSS via page name in Atomik theme

CVE-2026-8353 · Severity: medium · CVSS 4.8 · Published 2026-05-22

Technologies: Concrete CMS, concrete5/concrete5 (Packagist). Vendors: Concrete CMS, Packagist.

Executive brief

Concrete CMS, a platform used for building and managing websites, contains a security flaw in its 'Atomik' theme. A user with editing privileges can insert malicious scripts into a page name, which will then execute when other logged-in users visit specific account pages. This could allow an attacker to hijack user sessions, steal login credentials, or perform unauthorized actions on behalf of other users.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in Concrete CMS versions 9.0 through 9.5.0 within the Atomik theme. The flaw is rooted in the improper neutralization of input during web page generation (CWE-79) specifically involving page names. An authenticated attacker with 'editor' or higher privileges can inject a malicious JavaScript payload into a page name. This script executes in the browser context of any authenticated user who navigates to the affected account pages. Successful exploitation can lead to session hijacking, credential theft, and privilege escalation. The issue is addressed in Concrete CMS version 9.5.1.

Affected products

  • Concrete CMS Concrete CMS 9.0 to 9.5.0

Timeline

  • 2026-05-22: disclosed
  • 2026-05-22: advisory
  • 2026-05-22: patched: Fixed in version 9.5.1

References

Related threats