Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. (CVE-2026-81913) | HOL Guard CVE