Skip to main content
Loading…
    CVE-2026-8347 — Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog.  This can cause Cross-entity state tampering with view-only permission on one — CVE Database · The Intelligence Room