Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature (CVE-2026-81912) | HOL Guard CVE