CVE-2026-18117 | Concrete CMS up to 9.5.3 Edit Alias Dialog customAliasName cross site scripting
A vulnerability described as problematic has been identified in Concrete CMS up to 9.5.3. Affected by this issue is some unknown functionality of the component Edit Alias Dialog. The manipulation of the argument customAliasName results in cross site scripting.
This vulnerability is known as CVE-2026-18117. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More