CVE-2026-93659

critical

Description

Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data.

References

https://www.vulncheck.com/advisories/concrete-cms-community-store-before-2.7.8-stored-xss

https://github.com/concretecms-community-store/community_store/releases/tag/v2.7.8

https://github.com/concretecms-community-store/community_store/commit/2a802d6a5717f4e351ef21fdf8bdaf8061c40109

https://github.com/concretecms-community-store/community_store/blob/v2.7.7/elements/order_slip.php

https://github.com/concretecms-community-store/community_store

Details

Source: Mitre, NVD

Published: 2026-09-18

Updated: 2026-09-18

Risk Information

CVSS v2

Base Score: 8.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:N

Severity: High

CVSS v3

Base Score: 8.7

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Severity: High

CVSS v4

Base Score: 9.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

Severity: Critical

EPSS

EPSS: 0.00257