CVE-2026-81894 | Concrete CMS up to 9.5.2 Gallery block frontend.js append cross site scripting
A vulnerability categorized as problematic has been discovered in Concrete CMS up to 9.5.2. Affected is the function append of the file concrete/js/features/imagery/frontend.js of the component Gallery block. The manipulation results in cross site scripting.
This vulnerability is known as CVE-2026-81894. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More