System running
Last check: 2026-09-28 23:26:01 | Auto-updates every hour
752 PoCs
CybersecPlayground | The ultimate platform for cybersecurity learning & Bug Bounty Resources

CVE-CVE-2026-18110

Severity
HIGH
CVSS Score
7.5
Description

Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint (/ccm/system/user/autocomplete), which backs the "Preview as User" panel and other user-selector components. The endpoint validates only a CSRF-style access token that is bound to the selector's display options rather than to the caller's identity or permissions, and that token is issued to anonymous visitors because the selector renders without an authorization check. Because ...

PoCs for CVE-CVE-2026-18110

CVE-2026-18110-PoC
General 0
flenz00 2026-09-28
Master Cybersecurity | Join CybersecPlayground for Cybersecurity Learning & Bug Bounty Resources