Skip to main content

Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page CSS via a DOM sink,… (CVE-2026-18119)

0
High
Published: 09/14/2026 (09/14/2026, 21:31:44 UTC)
Source: GCVE Database

Description

Concrete CMS versions below 9.5.3 contain a stored cross-site scripting (XSS) vulnerability due to improper sanitization of custom style values in the Block Design dialog. This flaw allows an editor-level user to inject script code that executes in an context of an administrator's session, potentially enabling privilege escalation. The vulnerability has a high severity rating with a CVSS v4.0 score of 7.0.

CVSS v4.0

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
High
User Interaction
Passive
Vuln. Confidentiality
Low
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
Scope
X
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Affected software

Affected versions
<9.5.3

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/15/2026, 01:58:39 UTC

Technical Analysis

Concrete CMS versions prior to 9.5.3 do not sanitize custom style values entered in the Block Design dialog before embedding them into page CSS via a DOM sink. This lack of sanitization permits stored cross-site scripting (CWE-79), allowing an attacker with editor-level privileges to execute arbitrary scripts in an administrator's session. The vulnerability has a CVSS v4.0 base score of 7.0 (AV:N/AC:L/PR:H/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N), indicating network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability.

Potential Impact

An attacker with editor-level access can exploit this vulnerability to execute arbitrary scripts in the context of an administrator's session. This can lead to privilege escalation and unauthorized actions performed with administrator privileges. The vulnerability affects confidentiality, integrity, and availability of the affected system.

Mitigation Recommendations

A fix is available in Concrete CMS version 9.5.3 and later. Users should upgrade to version 9.5.3 or newer to remediate this vulnerability. No additional mitigations are specified.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-fjhh-g9g9-wm99
Osv Schema Version
1.4.0
Aliases
["CVE-2026-18119"]
Database Specific Severity
HIGH
Cvss Version
4.0

Threat ID: 6aa8a1c755bf5e2cf5f3e8da

Added to database: 09/15/2026, 01:39:19 UTC

Last enriched: 09/15/2026, 01:58:39 UTC

Last updated: 09/15/2026, 01:58:39 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses