CVE-2026-8203: Concrete CMS has Stored XSS through its height parameter
(updated )
Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validate or sanitize $height. Any user with editor privileges can inject malicious JavaScript that executes in the context of any visitor’s browser, potentially leading to session hijacking, credential theft, or other malicious actions.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-8203 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →