CVE-2026-8203HIGHCVSS 0.0

Concrete CMS has Stored XSS through its height parameter

Published May 21, 2026·Updated Jun 24, 2026

Description

Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validate or sanitize $height. Any user with editor privileges can inject malicious JavaScript that executes in the context of any visitor's browser, potentially leading to session hijacking, credential theft, or other malicious actions.

Affected Packages (1)

concrete5/concrete5COMPOSER
Fixed in 9.5.1

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free