CVE-2026-3242 | Concrete CMS up to 9.4.7 Switch Language Block cross site scripting (EUVD-2026-9360)
A vulnerability classified as problematic has been found in Concrete CMS up to 9.4.7. Affected is an unknown function of the component Switch Language Block Handler. This manipulation causes cross site scripting.
This vulnerability is registered as CVE-2026-3242. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.