GHSA-9v2g-37mp-qpxfHigh

Concrete CMS has Stored XSS through its height parameter

Published
May 21, 2026
Last Modified
June 24, 2026

🔗 CVE IDs covered (1)

📋 Description

Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validate or sanitize $height. Any user with editor privileges can inject malicious JavaScript that executes in the context of any visitor's browser, potentially leading to session hijacking, credential theft, or other malicious actions.

🎯 Affected products1

  • composer/concrete5/concrete5:< 9.5.1

🔗 References (3)