[High] CVE-2026-7888 – Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize()...
High CVE-2026-7888 Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious...