VYPR

Concretecms

by WordPress

CVEs (1)

  • CVE-2026-18122MedSep 11, 2026
    risk 0.39cvss epss

    Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization; the Concrete CMS REST API's Express entry collection endpoint disabled the per-entry view permission check. An OAuth token with read scope for an Express…