Vulnerabilities
Report: CVE-2026-8245 - Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination
CVE ID :CVE-2026-8245 Published : May 21, 2026, 10:16 p.m. | 46 minutes ago Description :Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection. Concrete\Core\Legacy\Pagination builds pagination links by raw-interpolating its $URL field into href=