GHSA-q9fm-mpg8-8jqm · Severity: low · Ecosystem: composer — Concrete CMS is vulnerable to Stored XSS via page name in the Atomik theme
Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inject arbitrary JavaScript that executes in the context of any authenticated user visiting the affected account pages. This can lead to session hijacking, credential theft, malicious actions performed on behalf of users, and potential privilege escalation. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.
Conclusion & alert: CVE-2026-8353 is rated Low Risk (9.9/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.15%). Mandatory action: Low composite risk—no urgent action required; patch on your normal maintenance cycle and revisit priority if CVSS or EPSS increases.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-23 | 0.20% | 0.15% | -0.05% |
| 2 | 2026-06-15 | 0.04% | 0.20% | +0.15% |
| 3 | 2026-05-23 | — | 0.04% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 2.1 | 4.0 | LOW |
|
— | — | ff5b8ace-8b95-4078-9743-eac1ca5451de |
| 4.8 | 3.1 | MEDIUM |
|
1.7 | 2.7 | [email protected] |
GHSA-q9fm-mpg8-8jqm · Severity: low · Ecosystem: composer — Concrete CMS is vulnerable to Stored XSS via page name in the Atomik theme
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| concretecms | concrete_cms | >= 9.0, < 9.5.1 | cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-notes | Release Notes Vendor Advisory |