THREAT OPS › Threat News › [NVD] CVE-2026-81898 — In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stored XSS in Express association views. A user able to submit an Address attribute could execute script in the session of any dashboard user who opened the af
[NVD] CVE-2026-81898 — In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stored XSS in Express association views. A user able to submit an Address attribute could execute script in the session of any dashboard user who opened the af
CVE-2026-81898 CVSS: None Published: 2026-09-15T18:19:26.800
In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stored XSS in Express association views. A user able to submit an Address attribute could execute script in the session of any dashboard user who opened the affected entry. The unescaped branch was reachable because
Indicators of compromise
- CVE-2026-81898cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81898