CSRF Vulnerability in Concrete CMS by Concrete5
CVE-2026-8410
2.3LOW
What is CVE-2026-8410?
Concrete CMS versions prior to 9.5.0 are susceptible to a Cross Site Request Forgery (CSRF) issue at the endpoint concrete/controllers/dialog/logs/bulk/delete. This vulnerability allows attackers to trick users into performing unintended actions on the site, potentially compromising user data and site integrity. It is imperative for users of affected versions to upgrade to at least 9.5.0 to mitigate this security risk.
Affected Version(s)
Concrete CMS 9.0 <= 9.5.0
