CVE-2026-18113
largeStored XSS via page names in Concrete CMS 9.0–9.5.2 Top Navigation Bar
Concrete CMS versions 9.0 through 9.5.2 fail to HTML-escape child page names rendered in the Top Navigation Bar block's dropdowns, allowing stored cross-site scripting (CWE-79). An attacker needs only the ability to create or rename a page: they place script in the child page's name, and the payload executes in the browser of any visitor, editor, or administrator who views the navigation and opens the affected dropdown. Because the script runs same-origin with the victim's privileges, it can read page content or silently perform any action available to that user, including administrators, effectively turning a limited editor account into full site compromise. Any site on 9.0–9.5.2 using the Top Navigation Bar block — especially those with multiple authors or self-service page creation — is affected. There is no known public proof of concept and no evidence of in-the-wild exploitation.
What to do: Upgrade Concrete CMS to a release later than 9.5.2 as soon as a patched version is available from the vendor. In the interim, restrict who can create or rename pages, and audit existing child page names (especially recently added or renamed ones) for embedded script tags or HTML payloads. Also review site logs and page revision history for suspicious page renames, since a successful payload would have executed against privileged users opening the navigation dropdown.
| Concrete CMS | 9.0 to 9.5.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing them into the page, so a user who could create or rename pages could store a script through a child page name and have it run in the browser of any visitor, editor, or administrator who viewed the navigation and opened the affected dropdown. In the Concrete CMS origin, the script executed with the victim's privileges and could read same-origin content or perform actions available to that user. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.5 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks labixiaoxin97 for reporting.
- Weakness
- CWE-79
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.