An issue was discovered in Concrete CMS through 8.5.5. There is an SVG sanitizer bypass.
- https://hackerone.com/reports/1102088
No PoCs found on GitHub currently.