CVE-2026-8340: Concrete CMS is vulnerable to CSRF via Backend\File::approveVersion
(updated )
Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edit_file_contents permission is CSRF’d into publishing an attacker-chosen previously-uploaded version (downgrade to an older version of a file, or activation of a co-editor’s unpublished version). Thanks Winston Crooker for reporting.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-8340 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →