Concrete CMS is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components (CVE-2026-7888) | HOL Guard CVE