CVE-2026-3240 | Concrete CMS up to 9.4.7 Question cross site scripting (EUVD-2026-9358)
A vulnerability marked as problematic has been reported in Concrete CMS up to 9.4.7. This affects an unknown function. The manipulation of the argument Question leads to cross site scripting.
This vulnerability is listed as CVE-2026-3240. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.