THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-81898 — In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stored XSS in Express association views. A user able to submit an Address attribute could execute script in the session of any dashboard user who opened the af

[NVD] CVE-2026-81898 — In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stored XSS in Express association views. A user able to submit an Address attribute could execute script in the session of any dashboard user who opened the af

mednvdPublished 2026-09-15

CVE-2026-81898 CVSS: None Published: 2026-09-15T18:19:26.800

In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stored XSS in Express association views. A user able to submit an Address attribute could execute script in the session of any dashboard user who opened the affected entry. The unescaped branch was reachable because

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81898