Medium severity4.8NVD Advisory· Published Mar 4, 2026· Updated Jun 17, 2026
CVE-2026-3244
CVE-2026-3244
Description
In Concrete CMS below version 9.4.8, A stored cross-site scripting (XSS) vulnerability exists in the search block where page names and content are rendered without proper HTML encoding in search results. This allows authenticated, rogue administrators to inject malicious JavaScript through page names that executes when users search for and view those pages in search results. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 4.8 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks zolpak for reporting
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
concrete5/concrete5Packagist | < 9.4.8 | 9.4.8 |
Affected products
3- Range: 5
Patches
Vulnerability mechanics
References
4- documentation.concretecms.org/9-x/developers/introduction/version-history/948-release-notesnvdPatchRelease NotesVendor AdvisoryWEB
- github.com/concretecms/concretecms/pull/12826nvdExploitIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-mm5f-5rqw-574fghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-3244ghsaADVISORY
News mentions
0No linked articles in our index yet.