CVE-2026-8139LOWCVSS 0.0

Concrete CMS is vulnerable to Stored XSS via external-link page cvName

Published May 22, 2026·Updated Jun 24, 2026

Description

Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updateCollectionAliasExternal bypasses being sanitized.

Affected Packages (1)

concrete5/concrete5COMPOSER
Fixed in 9.5.1

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free