
CVE-2026-8410 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete. The The Concrete CMS security team gave… https://www.cve.org/CVERecord?id=CVE-2026-8410
Post summary
The text announces a CSRF vulnerability in Concrete CMS 9 (before 9.5.0) affecting the logs bulk delete endpoint, without providing exploit details or patch information.
