
CVE-2026-8412 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache. The Concrete CMS security team gave this… https://www.cve.org/CVERecord?id=CVE-2026-8412
Post summary
The statement discloses CVE-2026-8412 as a CSRF vulnerability affecting Concrete CMS 9 versions prior to 9.5.0, specifying the affected endpoint and linking to the official CVE record.
