
CVE-2026-8409 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete. The The Concrete CMS security team gave this… https://www.cve.org/CVERecord?id=CVE-2026-8409
Post summary
CVE-2026-8409 describes a CSRF vulnerability in Concrete CMS 9 (prior to version 9.5.0) targeting the logs deletion dialog; no active exploitation or patch information is provided.
