Skip to main content
Loading…
    CVE-2026-8428 — Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update')) but the corresponding do_update() method in concrete/controllers/single_page/dashbo — CVE Database · The Intelligence Room