Skip to main content
Loading…
    CVE-2026-3241 — In Concrete CMS below version 9.4.8, a stored cross-site scripting (XSS) vulnerability exists in the "Legacy Form" block. An authenticated user with permissions to create or edit forms (e.g., — CVE Database · The Intelligence Room