Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block. (CVE-2026-81918)
Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block. A user with edit_page_contents permissions could store a payload which executes in the browser of any visitor who viewed a page where the block was configured to display a date-type attribute. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 4.8 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Oriol Ortiz for reporting.
AI Analysis
Technical Summary
Concrete CMS versions prior to 9.5.3 are vulnerable to a stored XSS attack via the Date Format field in the Page Attribute Display block. An attacker with edit_page_contents privileges can store a malicious payload that executes in the browser context of any visitor viewing a page where the block displays a date-type attribute. The vulnerability is tracked as CVE-2026-81918 and has a CVSS v4.0 score of 4.8 (AV:N/AC:L/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N). No known exploits in the wild have been reported.
Potential Impact
An attacker with edit_page_contents permissions can inject stored malicious scripts that execute in the browsers of users viewing affected pages. This can lead to unauthorized script execution, potentially enabling session hijacking or other client-side attacks. However, the attack requires elevated privileges (edit_page_contents) and user interaction (viewing the page), limiting the impact severity to medium.
Mitigation Recommendations
Upgrade Concrete CMS to version 9.5.3 or later, where this vulnerability has been fixed. Since the vulnerability affects versions below 9.5.3, applying the official update remediates the issue. No other mitigation guidance is provided or necessary.
Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block. (CVE-2026-81918)
Description
Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block. A user with edit_page_contents permissions could store a payload which executes in the browser of any visitor who viewed a page where the block was configured to display a date-type attribute. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 4.8 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Oriol Ortiz for reporting.
CVSS v4.0
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Concrete CMS versions prior to 9.5.3 are vulnerable to a stored XSS attack via the Date Format field in the Page Attribute Display block. An attacker with edit_page_contents privileges can store a malicious payload that executes in the browser context of any visitor viewing a page where the block displays a date-type attribute. The vulnerability is tracked as CVE-2026-81918 and has a CVSS v4.0 score of 4.8 (AV:N/AC:L/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N). No known exploits in the wild have been reported.
Potential Impact
An attacker with edit_page_contents permissions can inject stored malicious scripts that execute in the browsers of users viewing affected pages. This can lead to unauthorized script execution, potentially enabling session hijacking or other client-side attacks. However, the attack requires elevated privileges (edit_page_contents) and user interaction (viewing the page), limiting the impact severity to medium.
Mitigation Recommendations
Upgrade Concrete CMS to version 9.5.3 or later, where this vulnerability has been fixed. Since the vulnerability affects versions below 9.5.3, applying the official update remediates the issue. No other mitigation guidance is provided or necessary.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-j987-77r9-4hgr
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-81918"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6aa49ff555bf5e2cf5a86599
Added to database: 09/12/2026, 00:42:29 UTC
Last enriched: 09/12/2026, 00:45:54 UTC
Last updated: 09/12/2026, 00:47:06 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.