CVE-2026-3452 | Concrete CMS up to 9.4.7 Express Entry List Block unserialize columns deserialization (EUVD-2026-9356)
A vulnerability, which was classified as problematic, has been found in Concrete CMS up to 9.4.7. This vulnerability affects the function unserialize of the component Express Entry List Block Handler. Performing a manipulation of the argument columns results in deserialization.
This vulnerability is known as CVE-2026-3452. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.