CVE-2026-3241Disclosure(concretecms / concrete_cms)

LOWCVSS 4.8 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In Concrete CMS below version 9.4.8, a stored cross-site scripting (XSS) vulnerability exists in the "Legacy Form" block. An authenticated user with permissions to create or edit forms (e.g., a rogue administrator) can inject a persistent JavaScript payload into the options of a multiple-choice question (Checkbox List, Radio Buttons, or Select Box). This payload is then executed in the browser of any user who views the page containing the form. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 4.8 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks M3dium for reporting.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • concrete_cms

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Products
concrete_cms

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-04: 3Technical Details · 2026-03-04: 203-04
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3241 Stored XSS in Concrete CMS Legacy Form Block via Question Options https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3241

    Post summary

    This brief notice discloses a stored XSS vulnerability (CVE-2026-3241) affecting the Concrete CMS Legacy Form Block via question options, but provides no PoC, exploit code, active exploitation evidence, nor patch information.

    0000040
    4.0K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-3241 📊 Severity: 4.8 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3241 #CVE-2026-3241 #CVE #Medium #CyberSecurity #InfoSec https://t.co/5n9u2XC9xj

    Post summary

    The tweet announces a new CVE (CVE‑2026‑3241) with a moderate severity score but provides no technical details, exploit information, or evidence of active exploitation.

    0000042
    64 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3241 - Concrete CMS below version 9.4.8 is vulnerable to a stored cross-site scripting (XSS) in the "Legacy Form" block. Intel Report: https://ift.tt/yxPXrcQ

    Post summary

    Concrete CMS versions below 9.4.8 are vulnerable to stored XSS via the Legacy Form block (CVE-2026-3241). No PoC, exploit, or patch information is provided.

    0000035
    344 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appconcretecmsconcrete_cms---

Explore more