CVE-2026-93659 PUBLISHED

Concrete CMS Community Store before 2.7.8 Stored XSS

Assigner: VulnCheck
Reserved: 18.09.2026 Published: 18.09.2026 Updated: 18.09.2026

Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
CVSS Score: 9.3

Product Status

Vendor concretecms-community-store
Product community_store
Versions Default: unaffected
  • affected from 0 to 2.7.8 (excl.)
  • Version 2.7.8 is unaffected

Credits

  • Prince Edem Fiagbedzi finder

References

Problem Types

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE