Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-8353

Опубликовано: 22 мая 2026
Источник: nvd
CVSS3: 4.8
EPSS Низкий

Описание

Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inject arbitrary JavaScript that executes in the context of any authenticated user visiting the affected account pages. This can lead to session hijacking, credential theft, malicious actions performed on behalf of users, and potential privilege escalation. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Версия от 9.0 (включая) до 9.5.1 (исключая)

EPSS

Процентиль: 5%
0.00149
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

github
2 месяца назад

Concrete CMS is vulnerable to Stored XSS via page name in the Atomik theme

EPSS

Процентиль: 5%
0.00149
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79