Contact Zero

CVE-2026-18119

concretecms concrete cms

score 15HIGH 7

Summary

Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page CSS via a DOM sink, permitting stored cross-site scripting. An editor-level user could execute script in an administrator's session and escalate privileges. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.0 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Nguyen Manh Thuan for reporting.

Published 2026-09-14 · first seen here 2026-10-10

Analysis & write-ups

No technical write-up from a research team yet. Contact Zero checks Unit 42, Google/Mandiant, Microsoft, Talos, CrowdStrike, Rapid7, watchTowr and others several times a day, plus NVD and CISA reference links.

Where it shows in your logs

Server or web application · Cross-site scripting or request forgery medium confidence

What to look for

Data sources

Web server and WAF logs · ATT&CK DS0015 Application Log Content

Sentinel
W3CIISLogAppServiceHTTPLogsAzureDiagnostics (Application Gateway / Front Door WAF)_Im_WebSession
Splunk
Web.Webms:iis:autoaccess_combinedWAF / proxy sourcetypes
CrowdStrike
Falcon Next-Gen SIEM: third-party web / WAF / proxy logs

Process creation · ATT&CK DS0009 Process Creation

Sentinel
DeviceProcessEventsSecurityEvent (4688)Sysmon Event ID 1_Im_ProcessCreate
Splunk
Endpoint.ProcessesXmlWinEventLog:Microsoft-Windows-Sysmon/OperationalWinEventLog:Security (4688)
CrowdStrike
ProcessRollup2SyntheticProcessRollup2

File creation · ATT&CK DS0022 File Creation

Sentinel
DeviceFileEventsSysmon Event ID 11_Im_FileEvent
Splunk
Endpoint.FilesystemSysmon Event ID 11
CrowdStrike
NewExecutableWrittenNewScriptWritten*FileWritten events

Network connections · ATT&CK DS0029 Network Connection Creation / Network Traffic Flow

Sentinel
DeviceNetworkEventsCommonSecurityLog (firewall)_Im_NetworkSession
Splunk
Network_Traffic.All_TrafficFirewall sourcetypes (pan:traffic, fortigate_traffic, cisco:asa)
CrowdStrike
NetworkConnectIP4NetworkReceiveAcceptIP4NetworkConnectIP6

Authentication and sessions · ATT&CK DS0028 Logon Session Creation / DS0002 User Account Authentication

Sentinel
SigninLogsSecurityEvent (4624, 4625, 4648)DeviceLogonEventsIdentityLogonEvents_Im_Authentication
Splunk
Authentication.Authenticationpan:globalprotectVPN sourcetypes
CrowdStrike
UserLogonUserLogonFailed2Falcon Identity Protection events

A generic baseline worked out from the product type and weakness (CWE-79), not a detection. Check table and field names against your environment. Hunt queries for Sigma, Splunk, Sentinel and CrowdStrike are coming.

References