Cross Site Request Forgery Vulnerability in Concrete CMS by Concrete5
CVE-2026-8416

2.3LOW

Key Information:

Vendor
CVE Published:
21 May 2026

What is CVE-2026-8416?

Concrete CMS versions prior to 9.5.0 are susceptible to Cross Site Request Forgery (CSRF) in the addFavoriteFolder function within the file controller. This vulnerability allows attackers to trick authenticated users into making unintended actions on behalf of the user without their consent. It underscores the importance of implementing proper authorization checks and ensuring secure token validation to safeguard against unauthorized requests and maintain the integrity of user sessions.

Affected Version(s)

Concrete CMS 9.0 <= 9.5.0

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yonatan Drori (Tenzai)
.