CVE-2026-18120

CVE-2026-18120 published: Concrete CMS before 9.5.3 exposed a legacy Express entry search endpoint that returned entry result JSON without invoking the canViewExpressEntries() permission check applied by the normal dashboard and CSV Export flow. An unauthenticated visitor who knew o...

View full NVD advisory → ← Back to CVE watch