Cross Site Request Forgery in Concrete CMS Affects Versions Prior to 9.5.0
CVE-2026-8433
2.3LOW
What is CVE-2026-8433?
Concrete CMS versions prior to 9.5.0 are susceptible to a Cross Site Request Forgery (CSRF) vulnerability in the file rescan function within the backend controller. This flaw can allow unauthorized commands to be transmitted, potentially compromising the integrity of the application. Users are advised to update to the latest version to mitigate the associated risks.
Affected Version(s)
Concrete CMS 9.0 <= 9.5.0
