CVE-2026-81894
Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-image Caption field because the bundled Magnific Popup lightbox script (concrete/js/features/imagery/frontend.js) re-parses the attribute-decoded caption as HTML through jQuery's .append() in titleSrc instead of inserting it as text. A user with permission to edit a page containing a Gallery block can store a caption that executes in the browser of any visitor who opens that image's lightbox. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 8.5 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.25%
- CWE
- CWE-89
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- Concrete CMS Concrete CMS
Weakness type
Related vulnerabilities
- CVE-2026-76461 — Cisco Secure Email Gateway SQL Injection Vulnerability
- CVE-2026-67401 — A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTr
- CVE-2026-61667 — DIRAC: RCE in FileCatalog DatasetManager via SQL injection + eval
- CVE-2026-18658 — IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed
- CVE-2026-9163 — SQLi in GIS Informatics' GisLab Laboratory Management System
- CVE-2026-86460 — Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence
- CVE-2026-82232 — Apache Syncope: SQL injection via sort parameter in Task search
- CVE-2026-77051 — Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search