CVE-2026-87031 | Concrete CMS up to 9.5.3 REST API user creation endpoint Users.php add cross site scripting

SecurityVulns

A vulnerability classified as problematic has been found in Concrete CMS up to 9.5.3. The affected element is the function Add of the file concrete/src/Api/Controller/Users.php of the component REST API user creation endpoint. This manipulation causes cross site scripting.

This vulnerability is tracked as CVE-2026-87031. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More