Unknown · Concrete Cms · CVE-2026-8353
**Name of the Vulnerable Software and Affected Versions**
Concrete CMS versions 9.0 through 9.5.0
**Description**
Stored Cross-Site Scripting (XSS) exists in the Atomik theme. A user with editor privileges can inject arbitrary JavaScript through the page name, which then executes in the context of any authenticated user who visits the affected account pages. This may result in session hijacking, credential theft, unauthorized actions performed on behalf of users, and privilege escalation.
**Recommendations**
Update Concrete CMS to a version later than 9.5.0.