VYPR
Published Sep 15, 2026· Updated Sep 16, 2026· 1 source

Concrete CMS: 25 Vulnerabilities Disclosed in Single Batch, Ranging from XSS to Auth Bypass

Key findings • 25 CVEs disclosed for Concrete CMS on 2026-09-15, affecting versions prior to 9.5.3. • Three high-severity vulnerabilities include stored XSS and API-based user property modifi…

Key findings

  • 25 CVEs disclosed for Concrete CMS on 2026-09-15, affecting versions prior to 9.5.3.
  • Three high-severity vulnerabilities include stored XSS and API-based user property modification.
  • Numerous low-severity flaws involve CSRF, IDOR, and XSS due to authorization and sanitization issues.
  • All disclosed vulnerabilities are fixed in Concrete CMS version 9.5.3.

On September 15, 2026, a batch of 25 vulnerabilities was disclosed for Concrete CMS, affecting versions prior to 9.5.3. This significant disclosure event, spanning just three hours, includes three high-severity flaws and 22 low-severity issues, primarily stemming from insufficient authorization checks and improper input sanitization. The vulnerabilities present a range of risks, including stored and reflected cross-site scripting (XSS), cross-site request forgery (CSRF), insecure direct object references (IDOR), and server-side request forgery (SSRF).

Several vulnerabilities are related to cross-site scripting (XSS). CVE-2026-81927 and CVE-2026-81925 detail stored and reflected XSS in SVG file handling and conversation messages, respectively. CVE-2026-68534 describes stored XSS in Express entry labels, while CVE-2026-81899 highlights stored XSS in group folder names on the Members > Groups dashboard. Additionally, CVE-2026-81898 points to stored XSS in the Address attribute's country-less text formatter, and CVE-2026-18113 notes XSS via child page names in the Top Navigation Bar block.

Authorization flaws are another recurring theme. CVE-2026-18426 indicates that Express Form block control-management actions lacked proper block-level edit-permission checks. CVE-2026-18425 and CVE-2026-18113 reveal that sitemap reordering and REST API user property edits, respectively, did not enforce sufficient per-page or per-field permissions. Several other CVEs, including CVE-2026-18422, CVE-2026-81924, CVE-2026-81923, CVE-2026-18421, CVE-2026-68532, CVE-2026-68530, and CVE-2026-68529, are related to missing CSRF token validation or insufficient authorization checks in various dashboard and backend actions, such as multilingual page assignment, theme activation, SEO settings, block arrangement, and board management.

Insecure direct object reference (IDOR) vulnerabilities were also identified. CVE-2026-18423 describes an IDOR in Express saved search preset edit and delete dialogs, allowing users with view permissions to modify or delete presets owned by others. CVE-2026-81926 highlights an issue where colliding page paths were not properly escaped, leading to potential XSS when displayed in a confirmation dialog. Furthermore, CVE-2026-18424 details a server-side request forgery (SSRF) vulnerability related to remote file imports via cross-port reuse of DNS pins.

The high-severity vulnerabilities include CVE-2026-81899 (stored XSS in group folder names), CVE-2026-81898 (stored XSS in Address attribute formatting), and CVE-2026-18115 (unauthorized user property edits via the REST API). These critical flaws, alongside the numerous low-severity issues, underscore the importance of applying the latest security patches.

Concrete CMS has released version 9.5.3 to address all these vulnerabilities. Users are strongly advised to update to this version or later to mitigate the risks associated with this extensive batch of security flaws. The rapid disclosure of these 25 CVEs in a single, short window highlights a concentrated security event that requires immediate attention from all Concrete CMS administrators.

The batch of vulnerabilities disclosed on September 15, 2026, for Concrete CMS (versions prior to 9.5.3) primarily consists of authorization bypasses and cross-site scripting flaws. The timely patching of these issues is crucial for maintaining the security and integrity of Concrete CMS installations.

Key findings from this disclosure include:

  • Three high-severity vulnerabilities, including stored XSS and unauthorized user property modification via API.
  • Numerous low-severity flaws related to CSRF, IDOR, and reflected XSS across various modules.
  • A significant number of vulnerabilities stem from insufficient authorization checks and improper input sanitization.
  • All disclosed vulnerabilities are addressed in Concrete CMS version 9.5.3.

The Concrete CMS security team has addressed these issues in version 9.5.3. Users should update immediately.

Synthesized by Vypr AI