Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection.…
ConcreteCMS·CWE-83·Published 2026-05-21