CVE-2026-3241
Last modified
CVE-2026-3241 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. In Concrete CMS below version 9.4.8, a stored cross-site scripting (XSS) vulnerability exists in the "Legacy Form" block. An authenticated user with permissions to create or edit forms (e.g., a rogue administrator) can inject a persistent JavaScript payload into the options of a multiple-choice question (Checkbox List, Radio Buttons, or Select Box). EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
In Concrete CMS below version 9.4.8, a stored cross-site scripting (XSS) vulnerability exists in the "Legacy Form" block. An authenticated user with permissions to create or edit forms (e.g., a rogue administrator) can inject a persistent JavaScript payload into the options of a multiple-choice question (Checkbox List, Radio Buttons, or Select Box). This payload is then executed in the browser of any user who views the page containing the form. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 4.8 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks M3dium for reporting.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Concretecms | Concrete Cms | < 9.4.8 |
References
- https://documentation.concretecms.org/9-x/developers/introduction/version-history/948-release-notesPatch, Release Notes, Vendor Advisory
- https://github.com/concretecms/concretecms/pull/12826Exploit, Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-3241?
How severe is CVE-2026-3241?
How do I fix CVE-2026-3241?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-32404Missing Authorization vulnerability in Studio99 Studio99 WP …5.3
- CVE-2026-32405Exposure of Sensitive System Information to an Unauthorized …5.3
- CVE-2026-32406Missing Authorization vulnerability in WPClever WPC Product …4.3
- CVE-2026-32407Missing Authorization vulnerability in WPClever WPC Smart Wi…4.3
- CVE-2026-32408Missing Authorization vulnerability in themefusecom Brizy br…4.3
- CVE-2026-32409Missing Authorization vulnerability in WPMU DEV - Your All-i…5.3
- CVE-2026-32410Missing Authorization vulnerability in WBW Plugins WBW Curre…5.3
- CVE-2026-32411Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2026-32412Server-Side Request Forgery (SSRF) vulnerability in Gift Up!…5.4
- CVE-2026-32413Missing Authorization vulnerability in Maciej Bis Permalink …5.3
- CVE-2026-32414Improper Control of Generation of Code ('Code Injection') vu…7.2
- CVE-2026-32415Path Traversal: '.../...//' vulnerability in Bogdan Bendziuk…5
Are you affected by CVE-2026-3241?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
