---
id: CVE-2026-68528
title: >-
  Concrete CMS RSS Displayer block below version 9.5.3  rendered remote feed
  item titles without HTML escaping, resulting in stored cross-site scripting
summary: >-
  Concrete CMS RSS Displayer block below version 9.5.3  rendered remote feed
  item titles without HTML escaping, resulting in stored cross-site scripting.
  An attacker able to control a title in a syndicated feed could execute script
  in the …
severity: medium
cvss: 6
cvssVector: 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-79
vendor: Concrete CMS
product: Concrete CMS
affected:
  - concrete_cms >= 5.0.0 <= 9.5.2
published: '2026-09-11'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T20:17:22.430'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-68528'
references:
  - url: >-
      https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes
    label: ff5b8ace-8b95-4078-9743-eac1ca5451de
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-11T19:26:33.174720Z'
cvssSource: cna
ingestedAt: '2026-09-14T04:33:42.733Z'
epss: 0.00236
epssPercentile: 0.14816
---

## Overview

Concrete CMS RSS Displayer block below version 9.5.3  rendered remote feed item titles without HTML escaping, resulting in stored cross-site scripting. An attacker able to control a title in a syndicated feed could execute script in the site origin for any visitor to the affected page, including administrators, without holding an account on that site. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.0 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
