<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:concretecms:community_store:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aconcretecmscommunity_store/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 18 Sep 2026 16:09:09 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aconcretecmscommunity_store/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in Concrete CMS Community Store</title><link>https://feed.craftedsignal.io/briefs/2026-09-concrete-cms-xss/</link><pubDate>Fri, 18 Sep 2026 16:09:09 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-concrete-cms-xss/</guid><description>An unauthenticated stored XSS vulnerability in Concrete CMS Community Store versions prior to 2.7.8 allows attackers to execute malicious scripts in manager sessions via order fields.</description><content:encoded><![CDATA[<p>Concrete CMS Community Store versions before 2.7.8 are susceptible to a stored cross-site scripting (XSS) vulnerability due to improper input sanitization. The vulnerability exists because customer-supplied fields, specifically billing name, email, and phone, are rendered in the store's checkout and administrative interfaces without adequate HTML escaping. An unauthenticated attacker can exploit this flaw by submitting malicious JavaScript payloads through these fields during the order process. When an administrator or manager subsequently views the order details within the Concrete CMS dashboard, the malicious script executes within the context of the manager's authenticated session. This allows the attacker to perform unauthorized actions, including the creation of rogue administrative accounts or the exfiltration of sensitive order and customer data.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthenticated attackers to hijack administrative sessions, leading to full site compromise, unauthorized administrative actions, and potential data exfiltration. Given that the Community Store is a core component for e-commerce functionality, the impact covers all Concrete CMS instances utilizing this plugin, potentially affecting the integrity and confidentiality of store transaction data and administrative controls.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the Concrete CMS Community Store plugin to version 2.7.8 or later immediately.</li>
<li>Implement a web application firewall (WAF) rule to block common XSS payloads in parameters associated with billing or checkout forms.</li>
<li>Audit existing order records in the administrative console for suspicious script injection patterns in billing name, email, or phone fields.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>