THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-18113 — In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing them into the page, so a user who could create or rename pages could store a script through a child page name and have it run in the browser of any visitor, edi

[NVD] CVE-2026-18113 — In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing them into the page, so a user who could create or rename pages could store a script through a child page name and have it run in the browser of any visitor, edi

mednvdPublished 2026-09-15

CVE-2026-18113 CVSS: None Published: 2026-09-15T18:17:17.770

In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing them into the page, so a user who could create or rename pages could store a script through a child page name and have it run in the browser of any visitor, editor, or administrator who viewed the navigation and opene

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18113