PT-2026-42563 · Unknown · Concrete Cms

Yonatan Drori

·

Published

2026-05-21

·

Updated

2026-05-22

·

CVE-2026-8245

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Concrete CMS versions prior to 9.5.1
Description Reflected Cross-Site Scripting (XSS) occurs in Legacy Pagination through HTML attribute injection. The ConcreteCoreLegacyPagination class constructs pagination links by raw-interpolating the $URL variable into the href attribute of an anchor tag. An authenticated administrator or report viewer with access to the '/dashboard/reports/forms/legacy' endpoint can trigger the payload in their session by clicking a crafted URL.
Recommendations Update to a version newer than 9.5.0. Restrict access to the '/dashboard/reports/forms/legacy' endpoint to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-8245

Affected Products

Concrete Cms