CVE-2026-93659
Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and a
Summary
Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data.
Published 2026-09-18 · first seen here 2026-10-10
Exploit availability
Public exploit code lowers the bar for attackers, so prioritise patching and hunting. These repositories are unverified. Fake PoCs that contain malware are common, so never run them outside an isolated lab.
- prince325/CVE-2026-93659-writeup · ★0 · created 2026-09-19
Hunt & detect
Threat hunt brief, Sigma rule and Splunk / Sentinel / CrowdStrike queries are not available for this item yet.
References
- NVD entry
- https://github.com/concretecms-community-store/community_store
- https://github.com/concretecms-community-store/community_store/blob/v2.7.7/elements/order_slip.php
- https://github.com/concretecms-community-store/community_store/commit/2a802d6a5717f4e351ef21fdf8bdaf8061c40109
- https://github.com/concretecms-community-store/community_store/releases/tag/v2.7.8
- https://www.vulncheck.com/advisories/concrete-cms-community-store-before-2.7.8-stored-xss