Medium severity4.8NVD Advisory· Published Nov 14, 2022· Updated Jun 17, 2026
CVE-2022-43695
CVE-2022-43695
Description
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting (XSS) in dashboard/system/express/entities/associations because Concrete CMS allows association with an entity name that doesn’t exist or, if it does exist, contains XSS since it was not properly sanitized. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
concrete5/concrete5Packagist | < 8.5.10 | 8.5.10 |
concrete5/concrete5Packagist | >= 9.0.0, < 9.1.3 | 9.1.3 |
Affected products
3- Concrete CMS/Concrete CMSdescription
Patches
Vulnerability mechanics
References
7- documentation.concretecms.org/developers/introduction/version-history/8510-release-notesnvdRelease NotesVendor AdvisoryWEB
- documentation.concretecms.org/developers/introduction/version-history/913-release-notesnvdRelease NotesVendor AdvisoryWEB
- github.com/advisories/GHSA-8699-h45g-7hm8ghsaADVISORY
- github.com/concretecms/concretecms/releases/8.5.10nvdRelease NotesVendor AdvisoryWEB
- github.com/concretecms/concretecms/releases/9.1.3nvdRelease NotesVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-43695ghsaADVISORY
- www.concretecms.org/about/project-news/security/concrete-cms-security-advisory-2022-10-31nvdVendor AdvisoryWEB
News mentions
0No linked articles in our index yet.