Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Man-Like-Dan

#46055of 57,584
6.3Total CVSS
Vulnerabilities · 1
PT-2026-93870
6.3
2026-09-16
Concrete Cms · Concrete Cms · CVE-2026-18120
**Name of the Vulnerable Software and Affected Versions** Concrete CMS versions prior to 9.5.3 **Description** A legacy Express entry search endpoint returns entry result JSON without invoking the `canViewExpressEntries()` permission check. This allows an unauthenticated visitor who possesses an Express entity identifier to enumerate search results and disclose attribute values intended for privileged users. For Express entities where `supportsEntrySpecificPermissions()` returns false, per-entry permission filtering is further disabled through the `EntryList::ignorePermissions()` function. **Recommendations** Update to version 9.5.3 or later.