NONE · 0

CVE-2026-18116

Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in the workflow approval and deletion notifications shown in the dashboard "Waiting...

Vulnerability Description

Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in the workflow approval and deletion notifications shown in the dashboard "Waiting For Me" block. A registered user permitted to add events to a calendar governed by an approval workflow could submit an event whose name contained a script payload, which then executed in an administrator's browser when the pending request was displayed and could be used to create a new administrator account. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks v01demort for reporting.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-18116?

CVE-2026-18116 is a documented vulnerability. Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in the workflow approval and deletion notifications shown in the dashboard "Waiting...

How severe is CVE-2026-18116?

CVSS scoring is not yet available for CVE-2026-18116. Check NVD for updates.

Is there a patch for CVE-2026-18116?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.