
🚨*CVE* CVE-2026-8435 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion(). The Concrete CMS security team gav… https://www.cve.org/CVERecord?id=CVE-2026-8435 ----- Traducción: CVE-2026-8435 Con… http://infoflow.cloud`
Post summary
The post announces that Concrete CMS 9 before 9.5.0 suffers a CSRF flaw in the approveVersion endpoint; no PoC, exploit, active use, or patch is referenced.

