CVE-2021-22954
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.5%
exploitation probability
0.5%top 56% of all CVEs
observed exploitation
nono source reports it
A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an attacker to make requests on behalf of other users.
Affected products
n/a · https://github.com/concrete5/concrete5