Feed/CVE-2026-8340
CVE-2026-8340LOWCVSS 0.0

Concrete CMS is vulnerable to CSRF via Backend\File::approveVersion

Published May 26, 2026·Updated Jun 29, 2026

NVD Description

Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edit_file_contents permission is CSRF'd into publishing an attacker-chosen previously-uploaded version (downgrade to an older version of a file, or activation of a co-editor's unpublished version). Thanks Winston Crooker for reporting.

Affected Packages (1)

concrete5/concrete5COMPOSER
Fixed in 9.5.1

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free