Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion() (CVE-2026-8435) | HOL Guard CVE