CVE-2026-18120 | Concrete CMS up to 9.5.2 Entry Search canViewExpressEntries information disclosure
A vulnerability was found in Concrete CMS up to 9.5.2 and classified as problematic. This vulnerability affects the function canViewExpressEntries of the component Entry Search. Such manipulation leads to information disclosure.
This vulnerability is documented as CVE-2026-18120. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More