Concrete CMS Community Store before 2.7.8 Stored XSS
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.3epss 0.3%
from disclosure to weapon1 days
Published on NVDSep 18
1st PoC+1d
exploitation probability
0.3%top 82% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Affected products
concretecms-community-store · community_storepublic PoCs found — 1
githubgithub.com/prince325/CVE-2026-93659-writeup★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://github.com/concretecms-community-store/community_storehttps://github.com/concretecms-community-store/community_store/blob/v2.7.7/elements/order_slip.phphttps://github.com/concretecms-community-store/community_store/commit/2a802d6a5717f4e351ef21fdf8bdaf8061c40109https://github.com/concretecms-community-store/community_store/releases/tag/v2.7.8https://www.vulncheck.com/advisories/concrete-cms-community-store-before-2.7.8-stored-xss