
CVE-2026-8411 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete. The Concrete CMS security team gave this… https://www.cve.org/CVERecord?id=CVE-2026-8411
Post summary
A CSRF vulnerability (CVE-2026-8411) affects Concrete CMS 9 prior to 9.5.0, targeting the bulk delete dialog. The notice provides technical details but no PoC, exploit code, patch, or evidence of active exploitation.
