CVE-2026-3244
Last modified
CVE-2026-3244 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. In Concrete CMS below version 9.4.8, A stored cross-site scripting (XSS) vulnerability exists in the search block where page names and content are rendered without proper HTML encoding in search results. This allows authenticated, rogue administrators to inject malicious JavaScript through page names that executes when users search for and view those pages in search results. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 4.8 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
In Concrete CMS below version 9.4.8, A stored cross-site scripting (XSS) vulnerability exists in the search block where page names and content are rendered without proper HTML encoding in search results. This allows authenticated, rogue administrators to inject malicious JavaScript through page names that executes when users search for and view those pages in search results. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 4.8 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks zolpak for reporting
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Concretecms | Concrete Cms | < 9.4.8 |
References
- https://documentation.concretecms.org/9-x/developers/introduction/version-history/948-release-notesPatch, Release Notes, Vendor Advisory
- https://github.com/concretecms/concretecms/pull/12826Exploit, Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-3244?
How severe is CVE-2026-3244?
How do I fix CVE-2026-3244?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-32434Missing Authorization vulnerability in vowelweb VW Fitness v…5.3
- CVE-2026-32435Missing Authorization vulnerability in vowelweb VW Pet Shop …5.3
- CVE-2026-32436Missing Authorization vulnerability in vowelweb VW Photograp…5.3
- CVE-2026-32437Missing Authorization vulnerability in vowelweb VW Portfolio…5.3
- CVE-2026-32438Missing Authorization vulnerability in vowelweb VW School Ed…5.3
- CVE-2026-32439Missing Authorization vulnerability in WebGeniusLab BigHeart…5.3
- CVE-2026-32440Missing Authorization vulnerability in Ex-Themes WP Food wp-…5.3
- CVE-2026-32441Missing Authorization vulnerability in WebToffee Comments Im…7.7
- CVE-2026-32442Missing Authorization vulnerability in E2Pdf e2pdf e2pdf all…5
- CVE-2026-32443Cross-Site Request Forgery (CSRF) vulnerability in Josh Kohl…6.5
- CVE-2026-32445Missing Authorization vulnerability in Elementor Elementor W…2.7
- CVE-2026-32446Missing Authorization vulnerability in Syed Balkhi Contact F…4.3
Are you affected by CVE-2026-3244?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
