---
id: CVE-2026-18116
title: >-
  Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization
  and rendered them without HTML escaping in the workflow approval and deletion
  notifications shown in the dashboard "Waiting For Me" block
summary: >-
  Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization
  and rendered them without HTML escaping in the workflow approval and deletion
  notifications shown in the dashboard "Waiting For Me" block. A registered user
  per…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: concretecms
product: concrete_cms
affected:
  - 'concrete_cms >= 8.3.0, < 9.5.3'
patched:
  - concrete_cms 9.5.3
published: '2026-09-14'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T17:49:50.103'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18116'
references:
  - url: >-
      https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes
    label: ff5b8ace-8b95-4078-9743-eac1ca5451de
tags:
  - nvd
  - cve.org
epss: 0.00151
epssPercentile: 0.03556
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-15T13:39:06.755166Z'
scores:
  nvd: 6.1
  cna: 7.3
ingestedAt: '2026-09-14T23:17:06.521Z'
---

## Overview

Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in the workflow approval and deletion notifications shown in the dashboard "Waiting For Me" block. A registered user permitted to add events to a calendar governed by an approval workflow could submit an event whose name contained a script payload, which then executed in an administrator's browser when the pending request was displayed and could be used to create a new administrator account. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks v01demort for reporting.

## Affected

- `concrete_cms >= 8.3.0, < 9.5.3`

## Remediation

Upgrade past the affected range:

- `concrete_cms 9.5.3`
