Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS via Page Container icon (CVE-2026-81903) | HOL Guard CVE