CVE-2026-8353
Published May 22, 2026Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inject arbitrary JavaScript that executes in the context of any…
- evidence mentions
- 1
- Buzz score
- 11.9