← back
CVE-2026-93659criticalCWE-79

Concrete CMS Community Store before 2.7.8 Stored XSS

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9.3epss 0.3%
from disclosure to weapon1 days
Published on NVDSep 18
1st PoC+1d
exploitation probability
0.3%top 82% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.