Contact Zero

CVE-2026-93659

Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and a

score 30Public PoC ×1HIGH 8.6

Summary

Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data.

Published 2026-09-18 · first seen here 2026-10-10

Exploit availability

Public exploit code lowers the bar for attackers, so prioritise patching and hunting. These repositories are unverified. Fake PoCs that contain malware are common, so never run them outside an isolated lab.

Hunt & detect

Threat hunt brief, Sigma rule and Splunk / Sentinel / CrowdStrike queries are not available for this item yet.

References