Concrete CMS before 9.5.3 is vulnerable to Stored XSS via SVG upload in "Reject" sanitization mode (CVE-2026-81927) | HOL Guard CVE