
CVE-2026-8139 Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updateCollectionAliasExternal bypasses being sanitized. The Concrete CMS … https://www.cve.org/CVERecord?id=CVE-2026-8139
Post summary
Concrete CMS 9.5.0 and earlier have a stored XSS flaw caused by unsanitized external‑link pages. No patch, PoC, or exploitation activity is referenced.
