← Browse

CVE-2026-18119

Medium

Elevated severity or exploit probability.

CVSS base
9.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
0.3%
23.9th percentile
CISA KEV
Not listed
Weakness / dates
CWE-79
Published 2026-09-14 · modified 2026-09-18

CVSS breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Attack VectorNNetwork
Attack ComplexityLLow
Privileges RequiredLLow
User InteractionRRequired
ScopeCChanged
ConfidentialityHHigh
IntegrityHHigh
AvailabilityHHigh

Timeline

Description

Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page CSS via a DOM sink, permitting stored cross-site scripting. An editor-level user could execute script in an administrator's session and escalate privileges. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.0 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Nguyen Manh Thuan for reporting.

Affected

concretecms

References

Official: NVD · CVE.org