
CVE-2026-8413 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design. The Concrete CMS security team gave this… https://www.cve.org/CVERecord?id=CVE-2026-8413
Post summary
The post announces a CSRF vulnerability (CVE-2026-8413) affecting Concrete CMS 9 versions prior to 9.5.0, without mentioning exploitation, remediation, or a PoC.
