CVE-2026-7881MEDIUMCVSS 0.0

Concrete CMS is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail block

Published May 22, 2026·Updated Jun 24, 2026

Description

Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail block via the exEntryID parameter. This IDOR leads to unauthorized access to all Express form submissions. The Concrete CMS security team thanks Tristan Madani for reporting this issue.

Affected Packages (1)

concrete5/concrete5COMPOSER
Fixed in 9.5.1

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free