documentation.concretecms.orgrelease notes
https://documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-notes CVE-2026-8139
LOW
Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName
Record summary
CVE-2026-8139 has a selected CVSS score of 2.0 (low).
Description
Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updateCollectionAliasExternal bypasses being sanitized. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.0 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 22, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Concrete CMSBrowse Concrete CMS / Concrete CMSDefault status: unaffected | CVE List | 5.0 to ≤ 9.5.0 | affected |
concrete5/concrete5Browse Packagist / concrete5/concrete5 | GitHub Advisory | Before 9.5.1 · Fixed in 9.5.1 | affected |
References
3github.com
https://github.com/concretecms/concretecms nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-8139